By Interestana AI Editorial — AI-drafted, human-overseen. How we report
ClarityCheck Exposed Millions of Private Photos

The people-search tool ClarityCheck has exposed more than 9 million image files, including photographs of individuals' faces, due to a significant security misconfiguration. Independent security researcher Jeremiah Fowler discovered that an unsecured Amazon S3 bucket contained approximately 450 GB of images. These images were found in folders labeled "faces" and "profiles," making them accessible to anyone online via a URL embedded within the company's publicly available website code. The exposed data included what appeared to be profile images, screenshots, and other photographs of adults, teenagers, and children. ClarityCheck's website explicitly states that "Your reverse image search is private and secure," a claim now contradicted by this breach. In addition to the images, a second misconfiguration led to the public exposure of users' email addresses and phone numbers, further compromising personal information.
ClarityCheck operates as one of several "people-finder" tools that have emerged online in recent years. These platforms broadly assert their ability to search the internet, public records, and various databases to identify individuals. ClarityCheck's services extend to running searches based on phone numbers, email addresses, vehicle identification numbers, and names. Its photo-search functionality is advertised as capable of helping users "identify anyone in a photo" and locate associated social media profiles rapidly. The exposure of millions of images, particularly those containing identifiable faces, raises serious privacy concerns for the individuals whose photographs were stored and subsequently leaked. The nature of the data suggests a potential for misuse, including identity theft, stalking, or unauthorized surveillance, given the direct link to facial recognition capabilities.
The security lapse at ClarityCheck highlights ongoing challenges in data protection for online services that collect and process sensitive personal information. The use of unsecured cloud storage, such as Amazon S3 buckets, remains a common vulnerability that can lead to widespread data breaches. The fact that the files were organized into folders like "faces" and "profiles" indicates the sensitive nature of the content being stored. Fowler's research underscores the critical need for robust security audits and configurations for all cloud-based storage solutions, especially when dealing with personally identifiable information and imagery. The breach also brings attention to the broader implications of people-finder tools and the vast amounts of personal data they aggregate, often without explicit, informed consent for every use case. The potential for this data to be misused by malicious actors is a significant concern for regulators and privacy advocates alike.
Original source — read the full reporting at the publisher:
Read on Ars TechnicaGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.