Tech

ClarityCheck Data Breach Exposes Millions of Facial Images and Personal Details

Security researcher Jeremiah Fowler identified the misconfiguration, which stored 450GB of images including photos of children. ClarityCheck disputes the term "exposed" but has secured the database following contact from WIRED.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: WIRED · View original source
Reverse-Lookup Service Exposed Millions of Photos of People’s Faces
People-search tool left unsecured Amazon S3 bucket accessible, revealing biometric data and contact information

People-search platform ClarityCheck has left a database containing more than 9 million image files publicly accessible due to a misconfigured Amazon S3 bucket. The exposed data includes facial photographs, profile images, and screenshots of adults, teenagers, and children, alongside personal details such as email addresses and phone numbers.

Independent security researcher Jeremiah Fowler identified the vulnerability, which allowed unauthenticated access to folders named “faces” and “profiles” via a URL embedded in the company’s public website code. The database contained approximately 450GB of data. Additionally, API misconfigurations enabled users to retrieve personal information, including physical addresses and contact details, by manipulating website URLs with specific names.

ClarityCheck, which markets itself as a tool to identify individuals using photos, phone numbers, and public records, disputed the characterisation of the incident as a data exposure. A company spokesperson argued that the storage location was unindexed and not discoverable through ordinary web searches, stating that access required knowledge of a specific URL. The company also noted that the data included duplicate, cropped, and resized copies of files, rather than 9 million unique images.

Despite the company’s stance, security experts define data exposure as any instance where sensitive information is left accessible on the open internet without authentication. Mark Beare of Malwarebytes stated that a misconfigured storage bucket constitutes an exposure regardless of whether it was actively misused. The American Civil Liberties Union’s Rebecca Williams highlighted that systems relying on sensitive biometric data for verification carry inherent risks, even with improved security practices.

The exposure poses significant risks for identity theft and artificial intelligence training, particularly given the presence of images of children. Fowler warned that cybercriminals could utilise the data for catfishing or creating AI personas. ClarityCheck has since secured the database and improved its security reporting procedures after being contacted by WIRED in July.

Continue reading

More from Tech

Read next: Septuagint’s contested history comes into focus in review of Timothy Michael Law’s book
Read next: Ethernet Cable Length Matters Most at Higher Network Speeds
Read next: Engadget weighs MagSafe against USB-C for MacBook charging