A cloud database containing more than 9 million facial images was left exposed without authentication, according to security researcher Jeremiah Fowler. The 450 GB collection of images was traced to ClarityCheck, a US-registered company that provides reverse image search services to identify individuals and locate their social profiles and online presence. While ClarityCheck claims it does not use facial recognition technology, its service does enable users to identify people and find their names and social profiles through image searches.
The distinction between reverse image search and facial recognition may seem technical, but both approaches create privacy risks when images are stored insecurely. Reverse image search looks for identical or visually similar images using image embeddings, metadata, or indexed pages, while facial recognition detects faces, derives face-specific features, and compares them to a structured database. However, the practical outcome remains similar when facial images are linked to personal information such as names, social profiles, addresses, emails, or phone numbers.
Fowler discovered the unsecured database through URLs found in the site's code. ClarityCheck disputed that the data was publicly exposed, arguing that accessing it required unindexed URLs. However, the images did not require authentication to view once the URLs were known. The timeline of the exposure remains unclear, as it is unknown how long the database was accessible before Fowler's discovery. Despite earlier alerts from Fowler, ClarityCheck did not restrict access to the database until WIRED contacted the company in July.
The exposure creates significant risks because facial images serve as persistent identifiers that cannot be changed like passwords or other credentials. When images are linked with personal information, they could potentially be misused for impersonation, targeted phishing, doxxing, or catfishing. People finder tools like ClarityCheck aggregate public records, contact data, and social footprints, but they rely on user checkboxes to confirm permission to upload images, a system that cannot prevent misuse.
Security experts recommend several precautions when using such services. Users should not upload photos of others without permission or legal right, and should carefully consider how their own images will be used, stored, and secured before uploading. Before using any service, users should review policies on image retention, deletion, AI model training use, storage, and third-party sharing. If someone finds their image in search results, they should save the URL and screenshots, request delisting from the search service, and seek removal from the original hosting platform.
Source: https://www.malwarebytes.com/blog/privacy/2026/08/9-million-images-of-peoples-faces-exposed-by-reverse-lookup-service


