A security researcher found ClarityCheck, a people-search tool, left more than 9 million facial photos and 450 GB of images exposed in an unsecured Amazon S3 bucket. The database included profile images, screenshots, and photos of adults, teenagers, and children, stored in folders labeled “faces” and “profiles.” The exposure lasted for months before ClarityCheck secured the bucket after being contacted by WIRED in July.
The misconfiguration extended beyond images. ClarityCheck’s APIs were also misconfigured, allowing anyone to manipulate URLs to reveal personal details like email addresses, phone numbers, and physical addresses by entering names. The company disputes the term “exposed,” arguing access required a specific, unindexed URL, but security experts define exposure as any unauthorized access risk, regardless of discoverability.
ClarityCheck’s face-search feature uses uploaded photos to generate reports linking images to online identities, including names, addresses, and social media profiles. The tool’s reliance on sensitive biometric data heightens risks of misuse, such as scams or AI-powered impersonation. Fowler warns that exposed photos could be scraped for training AI models or used in fraud schemes. ClarityCheck says it has improved security reporting procedures but did not address the broader implications of its data collection practices.


