9 Million Facial Images Exposed Online: A Warning For Cork Readers

9 Million Facial Images Exposed Online: A Warning For Cork Readers

A security researcher has discovered more than 9 million photographs, including images of children, left exposed online by a reverse image search company, prompting fresh warnings for anyone who uploads personal photos to identification services.

Security researcher Jeremiah Fowler found an unsecured cloud database containing more than 9 million image files, according to reports by WIRED and ExpressVPN, where Fowler shared his findings. The database, some 450GB in size, was traced to a US-registered company called ClarityCheck.

The images were stored in an Amazon S3 bucket that required no password or encryption to access, in folders named "faces" and "profiles". The bucket's URL could be found within ClarityCheck's own publicly available website code, meaning no special hacking skills were needed to view the files.

In its own words, ClarityCheck states: "Use reverse image search to identify anyone in a photo. Find names, social profiles, and online presence in seconds." Its website also tells users: "Your reverse image search is private and secure."

Fowler said the exposed files appeared to include profile photos, screenshots, and other images of adults, teenagers, and children. He warned that facial images could be scraped and used to train AI models without a person's knowledge.

Jeremiah Fowler, Security Researcher:

"An AI bot could crawl it, extract faces, and use them for training. And there are lots of pictures of kids in there."

A separate misconfiguration also exposed people's email addresses, phone numbers, and physical addresses through the company's own lookup system, without requiring any special access.

ClarityCheck disputed that the data had been publicly exposed, arguing that reaching it required an unindexed URL. However, no authentication was needed to view the files, and Fowler was able to locate the URL through the company's own website code. The company secured the database only after WIRED contacted it in July, though Fowler says his earlier attempts to alert ClarityCheck went unanswered, and the bucket may have been exposed for months beforehand.

ClarityCheck requires anyone uploading a photo to confirm they own the image or have permission to use it, but this cannot stop someone uploading a picture of another person without their knowledge.

For CSA readers in Cork, cases like this are a reminder that any photo uploaded to an online identification or people-search tool could end up stored insecurely, and for far longer than users might expect. Malwarebytes has issued the following advice for anyone using ClarityCheck or similar services:

  1. Do not upload a photo of someone else unless you have their permission or another clear legal right to do so.
  2. Think twice before uploading your own photo if you are not sure how it will be used, how long it will be stored, and how secure that storage is.
  3. Check a service's policies on image retention, deletion, AI model-training use, storage, third-party sharing, and removing images before using it.
  4. If you find yourself in a search result, save the URL and screenshots, request delisting from the search service, and seek removal from the original site or platform hosting the image.

Source: Malwarebytes, citing WIRED and ExpressVPN.

Follow our WhatsApp ChannelLive Alerts