A reverse image search service that promises private and secure photo lookups left more than 9 million image files publicly exposed, including photographs of people's faces, according to new findings from independent security researcher Jeremiah Fowler. The people-search tool ClarityCheck, which claims to help users identify individuals from photos and find social media profiles "in seconds," stored the images in an unsecured Amazon S3 bucket that anyone online could access through a URL included in the company's publicly available website code. A second misconfiguration also publicly exposed people's email addresses and phone numbers.

The exposed ClarityCheck database contained roughly 450 GB of images, including what appeared to be profile images, screenshots, and other photographs of adults, teenagers, and children, according to Fowler's research. All of the files were stored in folders labeled "faces" and "profiles." ClarityCheck secured the database after WIRED contacted the company in July, but Fowler warns the exposure seemingly lasted for months. His initial attempts to alert the company to the problem were unsuccessful.

Fowler points out that people whose faces were exposed may have had no idea ClarityCheck held their image, since the service is explicitly designed for identification and people don't typically seek to identify themselves or acquaintances they already know. "If you're trying to find out who a person is, you might not have authorization or permission, so people might not know that their image had been dumped into this database that was public," Fowler told WIRED. He added that an AI bot could crawl the database, extract faces, and use them for training, noting that "there are lots of pictures of kids in there." A ClarityCheck spokesperson told WIRED the company acted immediately to restrict access once the issue reached the appropriate teams, though the company disputed any characterization that the data was "exposed," arguing that an "ordinary member of the public" would not have come across it.

The security industry broadly, as well as the US federal government, considers data to be exposed if it could be accessed by people not intended to have access—particularly if it's reachable on the open internet without authentication requirements like a username and password. Mark Beare, head of consumer products at Malwarebytes, explained that "exposure is the state in which personal or sensitive data has been left accessible, discoverable, or otherwise put at risk of unauthorized access, whether or not anyone has yet taken or misused it." Accidental data exposures create risk for any personal information, but the danger is particularly acute for sensitive and unchangeable biometric data like face images. While ClarityCheck's website requires people to attest they have permission to upload photos, the nature of the service—helping users identify unknown individuals—means many subjects likely never consented to having their images stored in the company's database in the first place.

The exposure highlights the tension between services that promise privacy and the infrastructure vulnerabilities that can undermine those guarantees. Biometric data like facial images can't be changed if compromised, unlike passwords or credit card numbers, making such exposures permanent risks for affected individuals. Companies marketing tools that mine personal data face heightened responsibility to secure what they collect, especially when those images include children and when users may not know they're in the database at all.