Published · 22h agoSecurity2 min read
Nine million faces in an open bucket, and the vendor's answer was "the URL wasn't indexed"
A researcher found 450GB of uploaded photos with no authentication in front of them at US lookup service ClarityCheck. A face, unlike a password, cannot be reset.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Researcher Jeremiah Fowler discovered an unsecured database containing nearly 9.1 million facial images belonging to U.S. company ClarityCheck, according to Biometric Update.
- The ClarityCheck database housed approximately 450.2 GB of data.
- The exposed data included profile images, screenshots and photographs of adults, teens and children, stored unencrypted and without adequate security safeguards.
- Fowler found a cloud database containing more than 9 million image files accessible without authentication, and the bucket held some 450 GB of images, WIRED reports.
- The leaky bucket was traced back to a US-registered company called ClarityCheck.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Divide 450.2 GB by 9.1 million files and the average image works out at roughly 49 KB [18]. That is not a vault of high-resolution portraits; it fits what was reported in the store, profile pictures and screenshots [3]. Small files, but each one is the input side of a lookup: a photo someone pasted in to get back a name, social profiles and an online presence [6].
ClarityCheck's position, according to Malwarebytes' account, is that this was not a public exposure because reaching the files required an unindexed URL [8]. Unindexed and unreachable are different properties. Fowler obtained the URLs from the site's own code [8], which is the point at which obscurity stops being a control and becomes a description of how the storage was addressed. Nothing in the path asked for authentication [4].
The company also says it does not use facial recognition, while describing its image function as a way to identify people and find their names and social profiles [7]. For anyone whose photo is in the bucket, that distinction is a matter of internal architecture. What an attacker takes away is an image tied to a name, social accounts, and possibly an address, email or phone number, which is the raw material for impersonation, targeted phishing, doxxing and catfishing [12].
How long the store was open before Fowler found it is unknown [9]. That gap is the expensive part. Without a bounded window, nobody can scope who to notify or say whether a given face was copied, so there is no version of this incident in which the affected people get a clean answer. They were never the customers anyway; they were the query.
Fowler implies no wrongdoing by ClarityCheck and makes no claim of active exploitation, calling the risk hypothetical [14]. That caveat is worth keeping in view, because the failure on record is a storage decision rather than a theft. It is also the reason the story matters to anyone buying identity tooling: the same company sells reverse image search and identity verification [16], and the security floor under the verification data turned out to be an unlisted address. Fowler's own standard is the one to hold vendors to, which is that firms collecting facial biometric data should treat it as sensitive personally identifiable information and protect it accordingly [15].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Researcher Jeremiah Fowler discovered an unsecured database containing nearly 9.1 million facial images belonging to U.S. company ClarityCheck, according to Biometric Update.
- [3]
The exposed data included profile images, screenshots and photographs of adults, teens and children, stored unencrypted and without adequate security safeguards.
ReportedView cited source - [4]
Fowler found a cloud database containing more than 9 million image files accessible without authentication, and the bucket held some 450 GB of images, WIRED reports.
ReportedView cited source - [5]
The leaky bucket was traced back to a US-registered company called ClarityCheck.
ReportedView cited source - [6]
ClarityCheck describes its service as: "Use reverse image search to identify anyone in a photo. Find names, social profiles, and online presence in seconds."
ReportedView cited source
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- malwarebytes.com3d ago9 million images of people’s faces exposed by reverse lookup service
- scworld.comSC Staff3d agoUnsecured database exposes millions of facial biometrics
Additional citations
- Biometric Update, via SC World



