Tuesday, August 25, 2026

Independent technology reporting and practical analysis

Manila ·
CYBERSECURITY

Independent reporting, useful context, and practical analysis.

Back to Technomalist
Cybersecurity / news

Unsecured Database Exposed Millions of Face Photos from People-Search Service

A researcher found a 450GB ClarityCheck database with no password containing more than 9 million files, including face photos, accessible via a URL in the company's public code.

Featured image for Unsecured Database Exposed Millions of Face Photos from People-Search Service
Featured image for Unsecured Database Exposed Millions of Face Photos from People-Search Service

A database tied to ClarityCheck, a reverse image search service that promises privacy, was left without password protection and held more than nine million files, many containing photos of people's faces, according to a security researcher's findings reported by Digital Trends.

Researcher Jeremiah Fowler documented the exposure in research published by ExpressVPN. The storage volume, roughly 450 gigabytes, was accessible through a URL found in ClarityCheck's own publicly available website code, he said. The files sat in folders named "faces" and "profiles" and included profile pictures, screenshots, and other images of adults, teenagers, and children. ClarityCheck has since restricted access to the storage.

The service allows anyone to upload a photo and search for the person in it, potentially returning social media profiles and other identifying information. That design means the people whose faces appear in the database may never have visited ClarityCheck themselves. Fowler said some of the images appeared to come from social media, dating profiles, screenshots, and photographs, raising the possibility that individuals were unaware their faces were stored there. He also reported seeing timestamps that exceeded the company's stated 14-day retention period for uploaded images.

In a statement to WIRED, ClarityCheck disputed the description of the database as "publicly exposed." The company argued that the data could only be reached through a specific, unindexed URL. However, the files themselves were not password-protected, and Fowler said he discovered the URL in code available on ClarityCheck's website. No evidence has emerged that anyone maliciously accessed the database before it was secured, but an obscure link is not equivalent to access control, and security researchers caution that if one researcher could find it through public code, others might have as well.

A separate issue affected ClarityCheck's website APIs. According to WIRED, manipulating certain URLs and entering a person's name could reveal possible email addresses, phone numbers, and physical addresses without special access. Reports have not indicated that those identifying details were directly linked to the exposed photos.

Still, the incident illustrates a broader privacy risk: images of people who never signed up for a service can end up in unsecured storage, and the rise of AI-driven impersonation makes that more dangerous. The exposure also undercuts ClarityCheck's marketing claim that its reverse image search is private and secure.

See an error? Read our corrections policy or email [email protected].

MORE FROM TECHNOMALIST

Continue reading

View all
Featured image for Researchers Show Expired Visa Contactless Cards Can Be Revived for Fraud
Cybersecurity

Researchers Show Expired Visa Contactless Cards Can Be Revived for Fraud

Philips LatteGo 4400 Series espresso machine on a kitchen counter.
Guides

Philips LatteGo 4400 espresso machine drops to AU$613 on Amazon Australia

Alice talks to Nora and Frank
Entertainment

How AI and assistive tools are helping disabled actors like Steve Way thrive on 'Furious'