Reverse-Lookup Service Exposed Millions of Photos of People’s Faces

Staff
By Staff 10 Min Read

In the vast, often opaque ecosystem of the internet, we are frequently asked to trust that the platforms we use are safeguarding our most personal information. ClarityCheck, a website offering people-search services, assured its users of exactly that, prominently displaying a message that its reverse image search was “private and secure.” However, a recent investigation has revealed a starkly different reality. Independent security researcher Jeremiah Fowler discovered that the company’s operational practices fell catastrophically short of its public promises. The website had left a massive, unsecured database containing more than 9 million image files—including photographs of people’s faces—open to anyone with an internet connection. This wasn’t a sophisticated hack requiring specialized skills; it was a simple misconfiguration that potentially exposed some of the most intimate and sensitive data imaginable to the public, with no safeguards in place.

The scale of this exposure is difficult to overstate. While the core issue involved images, the findings paint a picture of a systemic failure in data handling. Fowler’s research revealed that the exposed ClarityCheck database held roughly 450 gigabytes of data. This digital trove included what appeared to be profile images, screenshots, and a diverse array of photographs featuring not just adults but also teenagers and children. The data was stored in an unsecured Amazon S3 bucket—a cloud storage service that is meant to be configured with specific security settings to control access. In this case, that security was absent. The files were neatly organized into folders with labels like “faces” and “profiles,” making the sensitive nature of the content chillingly clear. The vulnerability was compounded by the fact that these files were accessible through a simple URL that was embedded within the company’s own publicly available website code. This meant that access wasn’t just theoretically possible; the path to the data was effectively published for anyone who knew where to look, and a second, related misconfiguration even exposed users’ email addresses and phone numbers, layering on another level of potential harm.

To understand the gravity of this situation, one must first understand what ClarityCheck is and how it operates. It is part of a growing and controversial category of online services known as “people-finder” tools. These platforms claim to aggregate data from across the web, public records, and various other databases to help identify unknown individuals. ClarityCheck’s website advertises its ability to run searches based on phone numbers, email addresses, vehicle identification numbers, and even names. Most notably, its photo-search feature promises to “identify anyone in a photo” and locate their social media profiles “in a matter of seconds.” This is a service designed to unravel anonymity. The people who use such a tool are typically seeking to find out who someone is—whether out of curiosity, suspicion, or for more nefarious purposes. While the service may require users to attest that they have permission to upload a photo, the very nature of its function suggests that in many cases, the individuals being searched for have no idea their image is being used. Therefore, the subjects of these photos, who were the subject of this massive data exposure, likely had no knowledge that their facial images were sitting in an open, unsecured location on the internet, vulnerable to download, misuse, or exploitation.

Beyond the immediate privacy violation of having one’s image publicly accessible, the exposure of biometric data—such as facial images—carries a unique and lasting danger. We can change a password, cancel a credit card, or get a new ID number if those are stolen, but we cannot change our face. Facial recognition technology is rapidly advancing and being deployed across the globe for everything from unlocking phones to surveillance and law enforcement. If an AI bot or a malicious actor were to crawl the exposed database and extract these facial images, they could be used to create deepfakes, bypass security systems, or be fed into AI training models to improve facial recognition software. The researcher, Fowler, stressed this very point, noting that an automated bot could easily scrape the data. He described the collection as containing “lots of pictures of kids,” which elevates the risk to an even more serious level, as the identities of minors are particularly vulnerable and their data can be used for a range of predatory behaviors online.

In response to Fowler’s findings, ClarityCheck did eventually rectify the issue. After being contacted by WIRED, a spokesperson stated that the company “acted immediately to restrict access.” However, their public response was characterized by a degree of defensiveness and obfuscation. The company disputed the characterization of the data as “exposed,” arguing that an “ordinary member of the public” would not have stumbled upon it. They claimed that access required knowledge of a specific, unindexed URL that was not discoverable through standard use of the service or a general web search. This line of reasoning, however, is a common and flawed defense among companies that have suffered security lapses. The security industry, and the US federal government, operate under a much clearer and stricter definition of exposure. Data is considered exposed if it is accessible to anyone who is not intended to have access, especially if it is on the open internet without authentication requirements like a password. As one expert noted, the state of exposure means data has been left accessible and put at risk, regardless of whether anyone has yet taken or misused it. A misconfigured storage bucket is a textbook example of this.

The incident shines a harsh light on the vulnerabilities that can be introduced by so-called “people-finder” services. These companies profit from the exposure and monetization of personal data. Their entire business model is predicated on collecting vast troves of information about individuals, often without their explicit consent, and making it searchable. The promise of privacy and security on their websites is, in many ways, an ironic and hollow one, as the very purpose of the service is to facilitate the identification of people who may wish to remain anonymous. The ClarityCheck incident is not an isolated anomaly but rather a symptom of a broader security problem that plagues organizations that collect and hold large amounts of personal data without implementing robust security infrastructure. The fact that the database was left unsecured for an extended period, and that initial attempts to flag the issue were unsuccessful, further indicates a lack of a proactive security posture. The company only acted when contacted by a major media outlet, which is a reactive, rather than proactive, approach to protecting user data.

Ultimately, this story is a cautionary tale about the hidden costs of the digital age. While websites like ClarityCheck offer a seemingly convenient service, they tread on dangerously thin ethical and security ice. The exposure of over 9 million images, including those of children, is a stark reminder that sensitive biometric data must be held to the highest security standards. The company’s attempt to downplay the severity of the exposure by quibbling over the definition of the word “exposed” is a pattern of behavior that erodes public trust and underscores the need for stronger data protection laws and greater accountability. For the individuals whose faces were left in that unsecured folder, the risk is real, permanent, and potentially life-altering. They may never know that their digital likeness was available for anyone to download and use, but the consequences of that exposure could follow them for a lifetime. This incident serves as a powerful lesson for all of us: the convenience of a service, and the promises on its website, should never be mistaken for adequate security, and our digital identities are far more fragile and valuable than we often recognize.

Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *