Reverse-lookup service exposed millions of facial images and contact details
THE BRIEF
Researcher Jeremiah Fowler found that the files were stored in an Amazon S3 cloud bucket and could be reached through locations referenced in publicly available website code. A separate misconfiguration also exposed some email addresses and phone numbers. ClarityCheck restricted access after being contacted and said it improved its security-reporting procedures. The figure describes image files, not nine million confirmed individuals. ClarityCheck said the collection included duplicates, cropped versions and resized copies. There is no public evidence that criminals downloaded or misused the material, so this should be described as a confirmed exposure rather than a confirmed theft. The case is especially sensitive because people may not know that their photograph was submitted to a reverse-search service. Anyone who used the service, or whose image may have been uploaded by another person, has limited ability to replace biometric information. Follow-up messages claiming to offer removal or protection should be independently verified.
WHY IT MATTERS
Facial images can support impersonation, stalking, unwanted identification and more convincing social-engineering attacks when combined with phone numbers or email addresses. Unlike a password, a face cannot be changed after exposure. The incident also demonstrates a privacy gap in people-search services: the person shown in a photograph may not be the customer who uploaded it and may never have consented. Managers selecting identity-verification or lookup vendors should examine storage controls, deletion practices and whether data subjects have meaningful recourse. The result can be lost money, account disruption and long recovery work for affected people.
WHO SHOULD CARE
ClarityCheck users, people whose photographs may have been submitted, parents, privacy teams and organizations evaluating facial-search services should care because exposed images and contact data can create long-lived identification and impersonation risks. They need clear steps because delays can increase financial, privacy or operational harm.
WHAT TO DO NOW
- Do not respond to unsolicited services claiming they can remove an exposed image for a fee.
- Review accounts connected to an exposed email or phone number for unusual recovery attempts.
- Enable strong multi-factor authentication on email and social accounts.
- Search the service’s official privacy channel for deletion or access-request procedures.
- Organizations should verify that image-processing vendors use authenticated storage and defined retention periods.
- Document and report targeted harassment, impersonation or identity misuse to the relevant platform and authority.
VERIFICATION NOTE
Verified through Wired’s independent reporting, the researcher’s findings and ClarityCheck’s response. More than nine million image files were exposed, but that is not the number of unique people. Access was possible without authentication; there is no public proof of malicious downloading or subsequent abuse. The brief therefore uses “exposed,” not “stolen,” and preserves the company’s qualification about duplicates.