When someone uploads a photo to the people-search tool ClarityCheck, the website has a clear message: “Your reverse image search is private and secure.” New research, however, shows that the website left more than 9 million image files, including photographs of people’s faces, publicly exposed. And a second misconfiguration publicly exposed people’s email addresses and phone numbers. The gap between ClarityCheck’s privacy promise and the reality of its security posture raises urgent questions about how people-finder platforms handle some of the most sensitive data imaginable: the biometric information contained in a human face.
What the Exposed ClarityCheck Database Contained
Independent security researcher Jeremiah Fowler uncovered roughly 450 GB of images stored in an unsecured Amazon S3 bucket. The files included what appeared to be profile images, screenshots, and other photographs of adults, teenagers, and children. The bucket was organized into folders named “faces” and “profiles,” and the images could be accessed by anyone online through a URL embedded in the company’s publicly available website code. In total, more than 9 million image files were left open to the open internet without any authentication barrier.
Beyond the image database, a second misconfiguration exposed email addresses and phone numbers belonging to users or subjects of searches. This compounded the risk: an attacker who found the image bucket could also potentially correlate exposed contact details with specific faces, creating a powerful tool for identity theft, harassment, or social engineering.
How a People-Finder Tool Exposed Millions of Faces
ClarityCheck is one of a growing number of people-finder tools that promise to identify individuals from a single photo. The website says it can run searches on phone numbers, email addresses, vehicle identification numbers, and names. Its photo-search page claims to help “identify anyone in a photo” and find social media profiles “in seconds.” To deliver this service, ClarityCheck must collect and store large volumes of images — uploaded by users as search queries, and presumably scraped from public sources or previously submitted searches.
What makes the exposure especially troubling is the nature of the data. A name or phone number can be changed. A face, however, is biometric data — it is unique to an individual and virtually impossible to revoke or replace. Once a face image is leaked into the wild, it can be used for unauthorised facial recognition, deepfake generation, AI training datasets, or simply to track and identify individuals against their will.
Why the Storage Bucket Was Vulnerable
Amazon S3 buckets are a common cloud storage service used by companies of all sizes. They can be configured as private, requiring authentication to access, or public, allowing anyone with the URL to view or download files. In ClarityCheck’s case, the bucket was left public. Even more concerning, the URL was not hidden — it was exposed in the company’s own website source code, meaning that anyone who inspected the page could find it. This is not a sophisticated hack; it is a basic configuration error that security researchers and malicious actors alike routinely scan for across the internet.
Fowler told WIRED that the database appeared to have been exposed for months before he identified it. His initial efforts to alert the company were unsuccessful. It was only after WIRED contacted ClarityCheck in July that the company secured the image database.
ClarityCheck’s Response: A Dispute Over the Meaning of “Exposed”
In a statement sent to WIRED, a spokesperson for ClarityCheck said that the company appreciated Fowler’s efforts to alert them about the issues. “Once this was drawn to the attention of the appropriate teams, we acted immediately to restrict access,” the spokesperson said. On the surface, this sounds like a responsible reaction. But the company then disputed any characterization that the data was “exposed,” arguing that an “ordinary member of the public” would not have come across it.
“We do not accept that data in the temporary storage location was ‘publicly exposed,’ which implies large-scale public access,” the spokesperson said. “Access required knowledge of a specific, unindexed URL that was not discoverable through ordinary use of the ClarityCheck service or a general web search.”
What the Security Industry Says About Data Exposure
This argument — that data is not exposed if the URL is unindexed — runs directly counter to standard security definitions. The US federal government, through CISA, considers data to be exposed if it could be accessed by people who are not intended to have access, particularly if it is reachable on the open internet without authentication. The key word is “could,” not “did.” Exposure is the state of being accessible, regardless of whether anyone actually accessed it.
Mark Beare, head of consumer products at the security company Malwarebytes, put it plainly: “Exposure is the state in which personal or sensitive data has been left accessible, discoverable, or otherwise put at risk of unauthorized access, whether or not anyone has yet taken or misused it. A publicly reachable database backup, a misconfigured storage bucket, or credentials sitting in a system that a researcher can reach are all exposures.”
Security researchers routinely scan the internet for open S3 buckets, and tools exist to enumerate them at scale. The notion that an unindexed URL provides meaningful protection is outdated at best. In practice, once data is placed in a public bucket, it is only a matter of time before it is found — whether by a well-intentioned researcher, a commercial data broker, or a malicious actor.
The Risk to Individuals Whose Faces Were Exposed
The people whose images were stored in ClarityCheck’s database may have had no idea that the company held their photograph. As Fowler pointed out, the service is explicitly designed for identification — people upload photos of others to try to identify them. The subject of the search typically does not consent to having their image uploaded, stored, and potentially exposed. “If you’re trying to find out who a person is, you might not have authorization or permission, so people might not know that their image had been dumped into this database that was public,” Fowler told WIRED. “An AI bot could crawl it, extract faces, and use them for training. And there are lots of pictures of kids in there.”
The presence of children’s photographs elevates the severity of this exposure. Biometric data of minors is especially sensitive because children cannot meaningfully consent to its collection or use, and the long-term consequences of a leaked image — appearing in AI training datasets, being used for harassment years later — are impossible to predict or control.
The People-Finder Industry: A Growing Privacy Concern
ClarityCheck is far from the only company operating in this space. A wave of so-called people-finder or people-search tools has emerged over the past decade, offering reverse image searches, background checks, and identity lookups. These services often scrape data from social media, public records, and other sources to build profiles on individuals. The business model depends on collecting as much data as possible, and security is often an afterthought.
The category has drawn increasing scrutiny from regulators and privacy advocates. Data brokers and people-search sites have been responsible for some of the largest data exposures in recent years, often because they store vast amounts of sensitive information — names, addresses, phone numbers, email addresses, family relationships, and now facial images — in poorly secured cloud infrastructure.
What makes ClarityCheck’s case particularly notable is the combination of exposure types. The image database alone represents a biometric privacy risk. But the simultaneous exposure of email addresses and phone numbers means that a determined actor could link a face to a phone number or email address, enabling targeted phishing, impersonation, or physical location tracking.
How Does a Face Image Become a Permanent Liability?
Once a facial image is exposed, it cannot be “un-exposed.” Unlike a password, which can be reset, or a credit card number, which can be reissued, a face is immutable. Exposed face images can be used to train facial recognition models without the subject’s consent. They can be fed into AI systems to generate deepfakes. They can be used to bypass facial recognition security systems if the image is similar enough to a live person. And they can be sold on dark web markets to identity thieves, stalkers, or intelligence services.
The risk is not theoretical. Multiple companies have been caught scraping public and semi-public face databases to train commercial facial recognition systems. Clearview AI, for example, scraped billions of images from social media and other public sources without consent, leading to regulatory actions and lawsuits across multiple countries. An exposed bucket like ClarityCheck’s is a goldmine for any entity seeking to build or augment a facial recognition dataset.
What Users Should Know About Reverse Image Search Tools
Are reverse image search tools like ClarityCheck safe to use? No tool that uploads your image to a server for processing can guarantee that your image will not be stored, analysed, or exposed. Even if a company promises privacy and security, the underlying infrastructure may be misconfigured, as ClarityCheck’s was. The safest approach is to assume that any image you upload to an online service may persist indefinitely, and may be accessed by parties you did not intend.
For users who do need to reverse-image-search a photo, consider using local or client-side tools that process images on your own device rather than uploading them to a cloud server. If you must use an online service, research its security history, check whether it publishes a transparency report, and avoid uploading images of other people without their explicit consent.
The Broader Implications for Cloud Security and Biometric Data
The ClarityCheck exposure is a case study in how not to handle sensitive data. It illustrates several recurring failures in cloud security: misconfigured storage buckets, hardcoded or exposed URLs in front-end code, a lack of authentication on sensitive databases, and slow response to vulnerability reports. These are not new problems. They have been documented repeatedly across industries — from healthcare to finance to government. Yet companies continue to make the same mistakes.
Part of the issue is that many organizations treat cloud security as a checkbox exercise. They assume that because they are using a reputable provider like Amazon Web Services, their data is automatically secure. But AWS itself has repeatedly warned customers that bucket permissions are their responsibility, and that default settings may not be restrictive enough. The Shared Responsibility Model means that the cloud provider secures the infrastructure, but the customer secures the data.
Biometric data requires a higher standard of care. Unlike a credit card number, a face cannot be replaced. Unlike a password, a face cannot be changed. Any company that collects, stores, or processes facial images should treat them as a critical asset and apply the most stringent security controls available — encryption at rest and in transit, strict access controls, regular security audits, and a robust vulnerability disclosure program.
What Regulators and Policymakers Can Learn
The ClarityCheck case also highlights gaps in the regulatory landscape. In the United States, there is no comprehensive federal data privacy law that specifically addresses biometric data. A patchwork of state laws — such as the Illinois Biometric Information Privacy Act (BIPA), the California Consumer Privacy Act (CCPA), and others — provides some protections, but enforcement is uneven and many states have no biometric privacy law at all. In the European Union, the General Data Protection Regulation (GDPR) classifies biometric data as a special category of personal data requiring explicit consent and additional safeguards, but enforcement across different member states varies.
Even where strong laws exist, they are often reactive rather than preventive. A company can collect and store millions of facial images without meaningful oversight, and only face consequences after a breach or exposure is discovered — if then. Regulators increasingly recognize that the current approach is inadequate. The Federal Trade Commission has taken action against companies like Facebook and Amazon for misuse of facial data, and the FTC has signalled that it will continue to prioritize biometric privacy. But the pace of regulation lags behind the pace of data collection.
The Future of People-Search Tools and Privacy
The demand for people-search and reverse-image-search tools is unlikely to diminish. As more aspects of life move online, the ability to identify someone from a photograph will remain valuable for everything from journalism to dating to personal safety. But the ClarityCheck exposure should serve as a warning: these services operate in a largely unregulated space, and their security practices may not match the sensitivity of the data they handle.
For consumers, the safest course is to minimize the use of such tools, and when they must be used, to do so with the understanding that privacy promises are not guarantees. For companies in this space, the lesson is clear: if you build a service that collects biometric data, you must secure it as if your own privacy depends on it — because, in a very real sense, it does. And for regulators, the growing number of exposures involving facial images makes a compelling case for stronger, clearer rules about how biometric data is collected, stored, and protected.
The exposure of millions of faces through ClarityCheck is not an isolated incident. It is a symptom of a broader dysfunction in how personal data — especially biometric data — is handled by companies that have every incentive to collect it and, apparently, too little incentive to protect it. Until that equation changes, the next exposure is not a question of if, but when.