ClarityCheck, a facial identification tool, left approximately 9,042,977 image files, totaling 450.2GB of data, publicly accessible on an unsecured cloud server. The exposed data consisted primarily of facial images, including those of adults, teens, and children, stored in folders labeled “faces” and “profiles.”
The exposed database was neither password-protected nor encrypted, allowing public access for several months. Many of the uploaded images may have originated from third-party sources like private profiles, social media accounts, and dating apps, suggesting that the individuals depicted likely did not consent to their photos being uploaded to ClarityCheck.
Security researcher Jeremiah Fowler tracked the exposed database to ClarityCheck. The company acknowledged ownership of the data and stated that it has since secured the server, addressing the vulnerability that led to the public exposure of the images.
The exposure of these facial images and associated identities poses risks, including potential use by scammers. Access to face photos could facilitate identity impersonation for fraudulent activities, such as creating fake social media profiles to trick family and friends into sending money.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
ClarityCheck, a facial identification service, exposed over nine million face photos on an unsecured cloud server for several months. This data breach allowed public access to images likely uploaded without consent, raising significant privacy and security concerns.