A ClarityCheck Database Exposed 9 Million Face Images
A cloud storage database linked to the people-search service ClarityCheck was accessible without a password or encryption. Security researcher Jeremiah Fowler reported finding 9,042,977 image files, totaling 450.2GB, in folders labelled faces and profiles. In the limited sample he reviewed, the photographs showed adults, teenagers, and children.
ClarityCheck restricted access after it was notified and acknowledged the responsible disclosure. The public record does not establish how long the files were reachable, whether anyone else accessed or downloaded them, or whether any exposed photograph was used for identity theft or another crime. This was a public database exposure, not proof that someone broke into ClarityCheck's internal systems.
What the public record establishes. The database was restricted after responsible disclosure; its exposure duration, downstream access, and number of unique people remain unknown.
Data behind this diagram
| Area | What the sources establish | Boundary |
|---|---|---|
| Storage access | Publicly reachable without a password or encryption | Not evidence of an internal-system intrusion |
| Scale | 9,042,977 image files totaling 450.2GB | File count, not unique people |
| Contents | Faces and profiles folders; sampled adults, teenagers, and children | Raw images, not confirmed formal biometric templates |
| Response | Responsible disclosure, company acknowledgement, and restricted access | No longer public at publication |
| Retention | Terms said 14 days; researcher observed older timestamps | Number and reason for older files unknown |
| Unresolved | Exposure duration and downstream access | Only internal logs and forensics could answer |
What ClarityCheck does
ClarityCheck is a people-finder service. Its reverse image search lets a customer upload a photograph and look for places where the same person or image may appear online. The service also advertises searches using details such as a name, phone number, email address, or vehicle identification number.
That context matters because the people pictured may not be ClarityCheck customers. Someone can submit another person's photograph while trying to identify them, check a dating profile, or find related accounts. ClarityCheck tells users to upload only images they have a right to share, but the disclosure could not determine whether every person shown knew that their photograph had been submitted.
What was exposed
Fowler's original disclosure describes image files in a cloud database. The folders were named faces and profiles, and his sample included profile pictures, screenshots, and photographs. The database location was visible in ClarityCheck's public website code and could be opened by anyone who had the URL because it did not require authentication.
The number is a file count, not a count of unique people. In its response to WIRED, ClarityCheck said the total included duplicate, cropped, and resized copies, as well as non-image data. The reporting does not show that a name or contact record was attached to every photograph. It also documents raw face images, not formal biometric templates.
WIRED separately reported another ClarityCheck configuration issue that could reveal contact details through manipulated website URLs. That issue was also restricted after notice. It is a separate finding and does not show that those contact details were paired with every file in the image database.
ClarityCheck's response
Fowler says he sent a responsible disclosure notice as soon as he confirmed the database belonged to ClarityCheck. The company thanked him for bringing the sensitive-image exposure to its attention, and the database was no longer publicly accessible by the time his report was published.
ClarityCheck told WIRED that it acted immediately once the report reached the appropriate teams. It disputed the word "exposed" because the storage URL was specific, unindexed, and not discoverable through an ordinary search. A hard-to-find URL is not the same as access control, however: the files were reachable over the public internet without a username, password, or other authentication requirement.
The company also said there was no suggestion of malicious access and that it had improved its security-reporting process. The public record cannot test that claim either way: only ClarityCheck or its storage provider could use internal logs and a forensic review to determine who accessed the database.
Why a face photograph can identify someone
A face is not a secret in the same way as a password, but a photograph can still be an identifying record. Reverse image search uses the picture itself as the search input. A match can connect an otherwise unnamed photograph to a public profile, workplace page, school page, dating account, or other context.
A face photograph alone is generally not enough to steal someone's identity. It can still make impersonation more convincing, help someone assemble a profile from separate public sources, or give a scammer a believable image for a false account. Unlike a password, a person cannot replace their face after a photograph has circulated.
The risk is especially hard to assess for children because an adult may have submitted or published the image on their behalf. The disclosure confirms that children appeared in the sample. It does not establish who they were, why each image was uploaded, or that any image was misused.
The stated retention period did not match every timestamp
ClarityCheck's terms said uploaded reverse-search images would be stored temporarily and deleted after 14 days. Fowler reported seeing files with timestamps older than that stated retention period. The public reporting does not explain how many files exceeded 14 days, why they remained, or whether duplicate and derived images followed a different deletion process.
This discrepancy matters because short retention is only protective when deletion happens as described. The discrepancy does not, by itself, establish how long any single file was stored, and the exact period of public accessibility remains unknown.
What remains unknown
- How long access was open. Fowler's disclosure does not establish a start date for public access.
- Who accessed or copied the files. No public forensic findings show downstream access, downloading, or misuse.
- How many people were represented. The 9,042,977 total is a file count and included duplicate or derived copies.
- What accompanied each image. The sources do not show that every photograph had a name, email address, phone number, or social profile attached.
- Who operated the storage. Fowler linked the records to ClarityCheck but could not determine whether the company or a contractor directly managed the database.
- Whether every person consented. Users were required to affirm they had permission, but the disclosure could not verify consent image by image.
Practical steps without panic
- If you used ClarityCheck's photo search, ask what remains. Request a copy of the data associated with your account or search, ask when submitted images were deleted, and use any applicable deletion or privacy right.
- Check your own public image trail. Run a reverse image search on a few current and older photographs of yourself to see which profiles and pages they lead to. Our personal exposure audit gives a cautious process that avoids contacting or testing other people.
- Remove public copies you no longer need. Tighten profile visibility and ask site owners to remove old photographs, especially images of children. This cannot recover a copy someone already saved, but it can reduce easy matching.
- Prepare for impersonation, not a guaranteed attack. Tell close contacts to confirm unusual money requests, account-recovery messages, or urgent calls through a second channel. A familiar face in a profile is not proof that the person controls it.
- Report concrete misuse. If someone is using your photograph without permission, report the account to the platform, preserve the relevant URLs and dates, and contact your privacy or data-protection authority where applicable.
A face-image exposure does not require everyone to reset passwords or replace identity documents. Take those steps only if you also find evidence that an account, credential, or document was involved. The useful response here is to reduce unnecessary public images, verify suspicious contact, and seek a direct answer about retention if you submitted a photo.
Sources
- Jeremiah Fowler's original ClarityCheck disclosure, published by ExpressVPN
- WIRED's report and ClarityCheck response
- WIRED's public post summarizing the report
Frequently Asked Questions
Was this an intrusion into ClarityCheck systems?
The published findings describe a cloud storage database that was publicly reachable without a password or encryption. They do not establish that anyone broke into ClarityCheck systems or that malicious access occurred.
Were 9 million people identified in the database?
No. The reported count was 9,042,977 image files, not 9 million confirmed people. ClarityCheck said the count included duplicate, cropped, and resized copies. The number of unique people and whether a name was attached to each image are unknown.
Did the exposed files contain biometric templates?
The disclosure documented raw face photographs in folders labelled faces and profiles. It did not establish that the storage database contained formal biometric templates.
Did ClarityCheck restrict access after it was notified?
Yes. The researcher made a responsible disclosure, ClarityCheck acknowledged the report, and public access was restricted. The company disputed describing the unindexed storage location as publicly exposed, but said it acted once the issue reached the appropriate teams.
What should I do if my photo may have been submitted?
Ask ClarityCheck what it retains about your searches and request deletion where applicable. Check where your photos appear online, reduce public copies you no longer need, and tell close contacts to verify unusual messages that use your face or identity.