A massive database linked to reverse-lookup service ClarityCheck was left without password protection or encryption, potentially exposing more than nine million facial images.
Independent cybersecurity researcher Jeremiah Fowler discovered the publicly accessible storage, which contained approximately 450GB of data. ClarityCheck provides tools designed to identify unknown callers, verify contact information, and search for information about individuals online.
According to Fowler’s findings, the exposed collection included images of adults as well as teenagers and children. Some photographs appeared to originate from external sources, including social media platforms and dating websites. Fowler raised concerns that people appearing in the database may not have known their photographs had been collected or retained. ClarityCheck has disputed claims made about the exposure. Fowler’s report on the ClarityCheck database
The discovery also raised questions about ClarityCheck’s stated image-retention practices. Users were reportedly informed that photographs they uploaded would remain stored for 14 days before automatic deletion. Fowler, however, said he identified files carrying timestamps that appeared to extend beyond that period.
It remains unknown how long the database was accessible without protection or whether anyone else discovered or downloaded its contents. Fowler also could not establish whether ClarityCheck directly operated the exposed storage infrastructure or whether it was managed by an outside provider.
The nature of the leaked material creates different privacy concerns from breaches involving conventional account information. Large collections of facial photographs could potentially be processed using facial-recognition technology to identify or track individuals. Fowler warned that advances in AI make it increasingly possible to match facial images at scale even when photographs are not accompanied by names or other identifying information.
The researcher also highlighted the possibility of exposed photographs being incorporated into datasets used to develop or improve facial-recognition and surveillance systems. However, there is no confirmed evidence in the supplied findings that the ClarityCheck images have actually been used to train AI models.
Another concern is impersonation. Access to numerous photographs of the same person could provide useful material for creating deceptive profiles or more convincing AI-generated content. Images involving minors carry additional risks because generative tools can be misused to manipulate legitimate photographs into harmful synthetic material.
Unlike passwords or payment credentials, facial characteristics cannot simply be replaced following an exposure. That makes uncertainty surrounding the eventual use and circulation of such datasets particularly significant.
The incident leaves several important questions unresolved, including how long the database remained exposed, whether unauthorized parties accessed it, and exactly how the millions of images were originally collected.