< Back to all clusters
[TECHNOLOGY] · 5 sources

started · updated

ClarityCheck facial-identification tool exposed 9 million photos

A major privacy breach has been identified involving ClarityCheck, a people-finder tool that uses facial identification to search for individuals across social media and public records. Security researcher Jeremiah Fowler discovered that more than 9 million image files, totaling approximately 450 GB of data, were left publicly accessible on an unsecured Amazon S3 bucket for several months.

The exposed database included photographs of adults, teenagers, and children, stored in folders labeled “faces” and “profiles.” In addition to facial images, a separate misconfiguration exposed email addresses and phone numbers. Many of the images likely originated from third-party sources such as dating apps, social media profiles, or private screenshots, often without the knowledge or consent of the individuals pictured.

While ClarityCheck requires users to attest that they have permission to upload photos, researchers expressed skepticism regarding the practical enforcement of this policy. The company has since secured the data following reports of the exposure.

Entities

Amazon S3 · ClarityCheck · Jeremiah Fowler