People-search service ClarityCheck left a cloud database publicly accessible without authentication, exposing more than 9 million image files totaling roughly 450 GB, including photographs of people’s faces used by its reverse image lookup service. Reporting said the images could be reached through URLs embedded in the site’s code, undermining the company’s claims that the service was private and secure because the data was only available through an unindexed link. The exposed repository remained accessible until media outreach prompted action, despite earlier notification from researcher Jeremiah Fowler.
A separate misconfiguration also exposed users’ email addresses and phone numbers, expanding the incident from a privacy lapse to a broader personal-data exposure. Because ClarityCheck markets tools that can connect images to names and social profiles, the leak raised risks including targeted phishing, impersonation, doxxing, and catfishing, with the exposed face images described as sensitive biometric-adjacent data that could be abused if linked to contact information or online identities.

Map this exposure pattern across your cloud, code, and identities.
4 events from the most recent confirmed update back to the earliest known activity.
WIRED reported that ClarityCheck had publicly exposed more than 9 million image files through a misconfigured database despite marketing its reverse image search as 'private and secure.' The report identified unauthorized exposure of sensitive personal data, including face photos and, through a separate misconfiguration, email addresses and phone numbers.
The Malwarebytes report says the unrestricted database remained accessible until WIRED contacted ClarityCheck in July. ClarityCheck also had a second misconfiguration that exposed users' email addresses and phone numbers.
After discovering the exposed bucket, Jeremiah Fowler alerted ClarityCheck about the issue. The exact date is not stated in the references.
Researcher Jeremiah Fowler discovered a cloud database tied to ClarityCheck that was accessible without authentication and contained more than 9 million image files totaling about 450 GB. The exposed files included photographs of people's faces.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
9 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcescworld.com
Open sourcesecuritymagazine.com
Open sourcearstechnica.com
Open sourcemalware.news
Open sourcemalwarebytes.com
Open sourcewired.com
Open sourceexpressvpn.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.