Top Stories
3 outlets·3 reports

Reverse-lookup service exposed millions of photos of people’s faces

ThinkingNews Desk · how this was written

A reverse-lookup service marketed as a private, secure face-search tool inadvertently exposed a massive collection of images, making millions of people’s facial photographs publicly accessible. The breach affected roughly nine million photos, revealing the scale of the data leak and raising concerns about the security of such facial-recognition platforms.

Written from all 3 reports below, not from any single one.

How it was reported

  1. Wired·
    Reverse-Lookup Service Exposed Millions of Photos of People’s Faces

    Jeremiah Fowler discovered that ClarityCheck stored about 450 GB of images—over 9 million photos of adults, teens and children—in an unsecured Amazon S3 bucket, accessible via URLs found in the site’s public code. The same misconfiguration also exposed users’ email addresses and phone numbers, and the data remained publicly reachable for months before the company restricted access after being notified.

  2. The Next Web·
    A “private and secure” face-search tool left 9 million photos exposed

    ClarityCheck, a reverse-image search service, unintentionally exposed a 450 GB bucket containing more than 9 million face photos—including images of adults, teenagers and children—without any password protection, accessible via an unindexed URL found in its own website code. The same misconfiguration also allowed anyone to retrieve associated email addresses, phone numbers and physical addresses by altering certain web addresses, prompting the company to lock down the storage after being notified by researcher Jeremiah Fowler.

  3. Ars Technica·
    Reverse-lookup service exposed millions of photos of people’s faces

    Researcher Jeremiah Fowler discovered that ClarityCheck stored about 450 GB of images—including profile pictures, screenshots, and photos of adults, teens and children—in an unsecured Amazon S3 bucket, exposing over 9 million files via URLs in the site’s code. A separate misconfiguration also leaked users’ email addresses and phone numbers.

Related stories

Share: