ClarityCheck Exposed Over 9 Million Facial Images and Personal Data in Unsecured S3 Bucket
A recent investigation by independent security researcher **Jeremiah Fowler** has revealed a significant data exposure affecting **ClarityCheck**, a prominent people-search tool. The platform, which promises private and secure reverse image searches, left over 9 million image files, including sensitive facial photographs, and a trove of personal data publicly accessible through misconfigured **Amazon S3** buckets.
Despite **ClarityCheck**'s assurances of privacy and security, a critical misconfiguration led to the public exposure of approximately 450 GB of image data. This vast collection included profile pictures, screenshots, and other photographs of adults, teenagers, and children, all stored in an unsecured **Amazon S3** bucket.
The exposed files, organized into folders named "faces" and "profiles," were accessible to anyone online via a URL embedded within the company's publicly available website code. In addition to the image data, a separate misconfiguration also exposed users' email addresses and phone numbers.
**ClarityCheck** is one of many "people-finder" services that claim to identify individuals by searching various public records and databases. Its website explicitly states capabilities for searching by phone numbers, email addresses, vehicle identification numbers, names, and even identifying individuals from photos to find social media profiles.
While **ClarityCheck** secured the exposed image database after being contacted by **WIRED** in July, **Fowler** warns that the data was seemingly exposed for months prior. His initial attempts to alert the company to the vulnerability were reportedly unsuccessful.
The exposure of such sensitive and immutable biometric data, like facial images, presents significant risks. **Fowler** highlights that individuals whose faces were exposed might have been unaware that **ClarityCheck** held their images, especially given the service's design for identification purposes.
"If youβre trying to find out who a person is, you might not have authorization or permission, so people might not know that their image had been dumped into this database that was public," **Fowler** told **WIRED**. He further cautioned about the potential for AI bots to crawl the data, extract faces, and use them for training, noting the presence of many images of children.
In a statement to **WIRED**, a **ClarityCheck** spokesperson acknowledged **Fowler**'s efforts and stated, "Once this was drawn to the attention of the appropriate teams, we acted immediately to restrict access." However, the company disputed the characterization of the data as "publicly exposed," arguing that access required knowledge of a specific, unindexed URL not discoverable through ordinary use or web searches.
This stance contrasts with the broader security industry's definition of data exposure. As **Mark Beare**, head of consumer products at **Malwarebytes**, explains, "Exposure is the state in which personal or sensitive data has been left accessible, discoverable, or otherwise put at risk of unauthorized access, whether or not anyone has yet taken or misused it." He cites publicly reachable database backups, misconfigured storage buckets, and accessible credentials as examples of exposures, a definition supported by entities like the **US federal government** and **CISA**.