Product4 publishers3 min readPublished Updated
ClarityCheck exposed 450GB of photos plus a second leak of emails and phone numbers, according to researcher Jeremiah Fowler. The company disputes the word "exposed."
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
A people-search site whose upload page promises "Your reverse image search is private and secure" left more than 9 million image files, including photographs of people's faces, reachable on the open internet [1][2]. The tools that employees use to check who they are dealing with are themselves unassessed vendors holding third-party biometric-adjacent data, and this one had no lock on the door. According to research by independent security researcher Jeremiah Fowler, the exposed ClarityCheck store held roughly 450GB of images, including what appeared to be profile pictures, screenshots and other photographs of adults, teenagers and children, all sitting in an unsecured Amazon S3 bucket with folders named "faces" and "profiles" [3]. The access path is the part worth dwelling on: the bucket was reachable by anyone online through a URL included in the company's own publicly available website code [4]. A second misconfiguration exposed email addresses and phone numbers [5], and Fowler found the site's APIs were misconfigured such that its URLs could be manipulated to reveal data about people simply by entering names [6]. ClarityCheck secured the image database after WIRED contacted it in July, but Fowler says it appeared to have been exposed for months and that his initial attempts to flag the problem to the company were unsuccessful [7]. A company spokesperson told WIRED that "once this was drawn to the attention of the appropriate teams, we acted immediately to restrict access" [8]. The company disputes the characterisation that the data was exposed, saying an "ordinary member of the public" would not have come across it and that access "required knowledge of a specific, unindexed URL that was not discoverable through ordinary use of the ClarityCheck service or a general web search" [9]. It also said there is no suggestion of malicious access and that the files include duplicate, cropped and resized copies of the same images along with non-image data, not 9 million unique images [10]. It says it has improved its security reporting procedures [11]. On duplicates, the arithmetic is at least consistent with the company's account: 450GB spread across 9 million files averages about 51KB each, which is thumbnail and crop territory rather than originals [12]. On the unindexed URL, the definition is not the vendor's to set. The security industry and the US federal government treat data as exposed if it could be accessed by people not intended to have access, particularly if it is reachable on the open internet without an authentication requirement [13]. Mark Beare, head of consumer products at Malwarebytes, puts it as "the state in which personal or sensitive data has been left accessible, discoverable, or otherwise put at risk of unauthorized access, whether or not anyone has yet taken or misused it" [14]. A path published in your own front-end code is not obscurity. The operator problem sits in what the product is for. ClarityCheck says it can run searches on phone numbers, email addresses, vehicle identification numbers and names, and its photo-search page says it can help "identify anyone in a photo" and find social media profiles "in seconds" [15]. That is a description of work already being done inside recruiting, fraud, trust and safety and sales teams, and nothing about pasting a photo into a website touches procurement. The site asks uploaders to attest that they have permission to upload the photo [16]. Fowler's point is that the attestation is structurally hollow: the service exists to identify people, and people do not usually set out to identify themselves or people they already know, so those whose faces were in the bucket may have had no idea it held their image [17]. If someone in your organisation ran a candidate's or a counterparty's photo through it, your organisation moved a third party's face into a vendor it never reviewed, and it has no record that it happened.
Ranked by verification strength, evidence, and original report placement.
New research shows ClarityCheck left more than 9 million image files, including photographs of people's faces, publicly exposed.
According to findings from independent security researcher Jeremiah Fowler, the exposed ClarityCheck database contained roughly 450 GB of images, including what appeared to be profile images, screenshots and other photographs of adults, teenagers and children, all stored in an unsecured Amazon S3 bucket with files in folders named "faces" and "profiles".
The unsecured S3 bucket could be accessed by anyone online through a URL included in the company's publicly available website code.
ClarityCheck secured the image database after WIRED contacted the company in July, but Fowler warns it was seemingly exposed for months and his initial efforts to flag the problem to the company were unsuccessful.
A ClarityCheck spokesperson told WIRED: "Once this was drawn to the attention of the appropriate teams, we acted immediately to restrict access."
The company added that it has improved its security reporting procedures to help other researchers contact it in future.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named researcher findings with exact figures, vendor acknowledgment and hands-on verification
The core finding is specific and quantified (9,042,977 files, 450.2 GB, folders "faces" and "profiles"), attributed to a named researcher, reproduced verbatim by a second publisher, and effectively conceded by the company, which acknowledged ownership, restricted access and argued only about wording and unique-file counts. WIRED also verified the live product independently. It is capped short of high confidence because the exposure rests on a single researcher's investigation with no third-party audit, no access logs, and no independent confirmation of the months-long window.
Service demonstrably live at multi-million-file scale, but no disclosed user or revenue metrics
Adoption evidence is indirect: roughly 9 million stored image files (inflated by duplicates, crops and resizes, implying about 51 KB average per file) and a working paid report flow tested by a reporter show real, non-trivial usage of the upload feature. No source discloses users, customers, traffic, revenue or third-party integrations, so the level of uptake cannot be placed higher.
Headline counts run ahead of unique-record reality; the underlying failure is real
Slightly overstated. "9 million images of faces" is the load-bearing number in both headlines, yet the company says the set includes duplicates, crops, resizes and non-image data, and the researcher's own figures average about 51 KB per file, so unique affected people are certainly fewer than the file count. Downstream harm claims (AI training crawls, impersonation scams) are plausible but unevidenced. The gap is small, not large, because the misconfiguration, the second contact-data leak, the months-long window and the remediation are all substantiated, and the vendor's "unindexed URL" defence conflicts with the industry and US federal definition of exposure.
Disclosure researcher, defensive vendor, quoted security vendor and affiliate-funded aggregation all shape framing
Multiple visible interests: the independent researcher gains reputation from publicised finds and supplied the sole underlying dataset; ClarityCheck has direct commercial and legal reasons to dispute "exposed" and to minimise unique-record counts; a Malwarebytes executive who sells consumer protection is quoted defining exposure; and the secondary outlet pairs the story with self-protection advice and a block of affiliate shopping links. WIRED's own scoop incentive is present but is offset by its publication of the company rebuttal and of the de-duplication caveat.
Core facts solid and vendor-acknowledged; scope, victim count and harm remain unquantified
High confidence that an unauthenticated store of face images and a name-queryable contact-data endpoint existed and have been secured, since two publishers align on the figures and the operator conceded remediation. Lower confidence on how many distinct people were affected, how long the window truly was, and whether anyone other than the researcher accessed the data, all of which rest on a single investigation without logs or independent audit.
security
Nine million faces in an open bucket, and the vendor's answer was "the URL wasn't indexed"2 publishers
security
OpenAI's 13-17 tier turns teen AI safety into an age-assurance problem1 publisher
product
Apple's report cap blocked a seven-person firm with a patched Mac bug to its name1 publisher
security
OpenAI's Computer History writes a plaintext log of the workday. Decide before staff opt in.1 publisher
Publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026
1 article · August 20, 2026
1 article · August 20, 2026
1 article · August 19, 2026