Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

ClarityCheck’s image database left millions of face photos publicly accessible

Security researcher Jeremiah Fowler discovered that ClarityCheck stored over 9 million facial images in an unsecured Amazon S3 bucket, making them reachable by anyone with the URL.

Independent researcher Jeremiah Fowler found that ClarityCheck’s reverse-image search service kept more than 9 million face photos in an unprotected Amazon S3 bucket, amounting to about 450 GB of data. The bucket’s folders, labeled “faces” and “profiles,” could be reached via URLs present in the site’s source code, meaning anyone with the link could view the files. In addition, a misconfigured API let users retrieve email addresses, physical addresses and phone numbers simply by inserting a name into a URL.

After one outlet alerted the company, ClarityCheck restricted the bucket but argued the data required knowledge of specific, unindexed URLs and was therefore not “publicly exposed.” Security experts countered that any data reachable without authentication qualifies as exposure, especially when it includes immutable biometric information. The breach raises concerns that AI tools could scrape the images to train models or enable identity-theft, with particular risk for children whose pictures were also stored.

Why it matters

Unsecured biometric data can be harvested for fraud, AI training, or other malicious uses, threatening privacy for millions.

In this story

reverse image searchdata exposureAmazon S3 bucketbiometric dataprivacy breachAI trainingemail address leakphone number leaksecurity misconfiguration
Get the beta ↗