Reverse-lookup service exposed millions of photos of people’s faces

ThinkingNews Desk · how this was written
A reverse-lookup service marketed as a private, secure face-search tool inadvertently exposed a massive collection of images, making millions of people’s facial photographs publicly accessible. The breach affected roughly nine million photos, revealing the scale of the data leak and raising concerns about the security of such facial-recognition platforms.
Written from all 3 reports below, not from any single one.
How it was reported
- Wired·Reverse-Lookup Service Exposed Millions of Photos of People’s Faces
Jeremiah Fowler discovered that ClarityCheck stored about 450 GB of images—over 9 million photos of adults, teens and children—in an unsecured Amazon S3 bucket, accessible via URLs found in the site’s public code. The same misconfiguration also exposed users’ email addresses and phone numbers, and the data remained publicly reachable for months before the company restricted access after being notified.
- The Next Web·A “private and secure” face-search tool left 9 million photos exposed
ClarityCheck, a reverse-image search service, unintentionally exposed a 450 GB bucket containing more than 9 million face photos—including images of adults, teenagers and children—without any password protection, accessible via an unindexed URL found in its own website code. The same misconfiguration also allowed anyone to retrieve associated email addresses, phone numbers and physical addresses by altering certain web addresses, prompting the company to lock down the storage after being notified by researcher Jeremiah Fowler.
- Ars Technica·Reverse-lookup service exposed millions of photos of people’s faces
Researcher Jeremiah Fowler discovered that ClarityCheck stored about 450 GB of images—including profile pictures, screenshots, and photos of adults, teens and children—in an unsecured Amazon S3 bucket, exposing over 9 million files via URLs in the site’s code. A separate misconfiguration also leaked users’ email addresses and phone numbers.
Related stories
- Analysis: Meta discreetly added code for an unreleased "NameTag" face-recognition system for its AI glasses over multiple updates to the Meta AI app this year (Wired)4 outlets
- We now have a better understanding how OpenAI hacked into Hugging Face6 outlets
- Former Meta engineer probed over 30,000 private Facebook photos3 outlets
- Clarifai deletes 3 million photos that OkCupid provided to train facial recognition AI, report says4 outlets