READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

People-Search Site ClarityCheck Left 9 Million Face Photos Publicly Accessible Online

People-Search Site ClarityCheck Left 9 Million Face Photos Publicly Accessible Online
A security researcher found ClarityCheck, a reverse-image people-search service, had left roughly 450 GB of face photos, including images of children, sitting in an unsecured cloud storage bucket anyone could access. The company fixed it only after WIRED contacted them, and it disputes the images were ever truly "exposed." This is exactly the kind of unaccountable data-broker mess that should worry anyone who values privacy and thinks government has a legitimate role in setting basic security standards for companies hoarding biometric data.

A people-search website called ClarityCheck told users their reverse image searches were "private and secure." That claim didn't hold up.

Independent security researcher Jeremiah Fowler found the company had left more than 9 million image files publicly accessible online, according to WIRED. The exposed files, totaling roughly 450 GB, included profile photos, screenshots, and other pictures of adults, teenagers, and children, stored in folders labeled "faces" and "profiles."

The files sat in an unsecured Amazon S3 bucket, a common cloud storage tool. Fowler says the bucket could be accessed by anyone who found the URL, which was included in ClarityCheck's own publicly available website code. A second misconfiguration separately exposed users' email addresses and phone numbers, according to WIRED.

ClarityCheck is part of a growing industry of "people-finder" sites that scrape public records and other databases to help users track down information on individuals. Its website advertises searches by phone number, email, vehicle identification number, and name. Its photo-search tool claims it can "identify anyone in a photo" and locate someone's social media profiles "in seconds."

That business model is the root of the problem here. A site built specifically to identify strangers from a photo is, by definition, going to accumulate images of people who never agreed to be in its database and have no way of knowing they're in it.

Fowler made that point directly to WIRED: "If you're trying to find out who a person is, you might not have authorization or permission, so people might not know that their image had been dumped into this database that was public." He also flagged the AI risk, warning that a bot could have crawled the exposed bucket, scraped faces, and used them to train facial recognition models.

ClarityCheck's terms require users to attest they have permission to upload someone's photo. But that's an honor-system check with no real enforcement, and it does nothing for the people whose faces end up in the database without their knowledge in the first place.

Fowler says he tried to alert ClarityCheck about the exposure before going public and got nowhere initially. The company secured the database only after WIRED reached out in July, months after Fowler says the bucket was likely first exposed.

In a statement to WIRED, a ClarityCheck spokesperson said the company "appreciated" Fowler's effort to flag the issue and "acted immediately to restrict access" once the right people saw it. But the company also pushed back on the word "exposed," telling WIRED that characterizing the data that way wasn't accurate, though it did not offer a fuller explanation of what it believes actually happened.

A company facing bad press has an obvious incentive to downplay a breach. But it's also true that "publicly accessible if you know the URL" is a different animal than "actively hacked and stolen," and reasonable people can disagree about which word fits best. WIRED's reporting, based on Fowler's findings, is that the bucket had no authentication requirement and anyone online could reach it, which is the standard definition of an exposed database in the security research community. ClarityCheck has not disputed that anyone with the link could view the files; it disputes the framing, not the underlying facts as reported.

There's no indication in WIRED's reporting that biometric data was stolen or misused by a third party before the bucket was secured. No breach notification, lawsuit, or regulatory investigation has been announced in connection with this incident. That matters. An open door isn't the same as proof someone walked through it and took something.

Still, the exposure sits inside a data-broker industry that operates with almost no federal oversight. There's no comprehensive U.S. law governing how people-search sites collect, store, or secure biometric images, and states have moved unevenly on the issue, with Illinois' Biometric Information Privacy Act standing as one of the few strict exceptions. Companies like ClarityCheck are free to scrape faces into a database, sell access to strangers trying to identify other people, and face essentially no consequence if that database ends up sitting open on the internet for months.

Congress has talked about federal privacy legislation for years and passed nothing comprehensive. Until that changes, the incentive structure stays the same. Move fast, secure later, and hope a researcher like Fowler finds the hole before someone with worse intentions does.

The open question is how many other people-search sites are running the same kind of unsecured setup right now, and whether anyone in Washington is going to do more than write a strongly worded letter about it.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
WiredReverse-Lookup Service Exposed Millions of Photos of People’s Faces