The people-finder website ClarityCheck inadvertently left over 9 million image files and sensitive personal contact information accessible to the public due to server misconfigurations. The exposed database included biometric facial data, email addresses, and phone numbers that remained vulnerable for months before the company secured the files.
The Scale of the Exposure
Security researcher Jeremiah Fowler uncovered a massive data vulnerability within the people-search platform ClarityCheck, which had left approximately 450 GB of user data completely unsecured. The exposed information resided in an Amazon S3 bucket that lacked proper authentication, allowing anyone with the specific URL to view, download, or harvest the contents. The repository contained more than 9 million files, categorized into folders labeled as 'faces' and 'profiles.' These files consisted of a wide range of sensitive materials, including screenshots, profile images, and photographs depicting adults, teenagers, and children. The exposure was not limited to imagery; a separate misconfiguration in the site’s application programming interface allowed unauthorized individuals to manipulate URLs to retrieve private contact details, such as phone numbers and email addresses, simply by inputting a target's name. This oversight effectively turned a tool designed for private investigations into a public source of harvested personal and biometric data.
Risks to Sensitive Biometric Data
The exposure of facial imagery presents a distinct set of risks compared to other types of data breaches. Biometric information, such as the unique geometry of a human face, is permanent and cannot be reset like a password. Experts emphasize that the presence of children's photos in such a large, accessible database is particularly concerning. If malicious actors or automated bots were to scrape this repository, they could utilize the images for a variety of illicit activities, such as training artificial intelligence models or creating synthetic personas for catfishing and identity fraud. Because ClarityCheck’s service is predicated on identifying individuals without their explicit participation—often relying on users to upload photos of others—the victims of this exposure were largely unaware that their biometric footprints were being stored in a vulnerable, publicly accessible location by the company.
The Company’s Response and Security Perspective
ClarityCheck addressed the security lapses after being contacted by investigators, confirming that access to the affected buckets and API endpoints was restricted shortly thereafter. However, the company pushed back against the term 'publicly exposed,' arguing that the data was not indexed by search engines and required knowledge of specific, hidden URLs to access. The spokesperson maintained that the company does not believe this constituted large-scale public availability. Conversely, the cybersecurity community and federal standards reject this defense, noting that any database reachable on the open internet without password protection is officially considered exposed. Industry professionals like Mark Beare of Malwarebytes argue that the intent of the attacker is irrelevant; if data is reachable by unauthorized parties, it is inherently at risk. ClarityCheck eventually acknowledged the issue, stating they have since improved their reporting procedures to ensure future security vulnerabilities are managed more effectively.
Broader Implications for Data-Driven Services
This incident highlights the mounting danger posed by digital platforms that rely on the mass collection of sensitive information to fuel their business models. As services like ClarityCheck expand their capabilities to offer detailed reports on individuals—including location history, social media footprints, and dating profile links—the incentive to hoard vast quantities of personal data increases. Critics, including those from the American Civil Liberties Union, suggest that these business models are structurally predisposed to risk. Even if companies implement stricter data minimization practices, the foundational dependence on aggregate personal data makes complete security an elusive goal. The ClarityCheck incident serves as a stark reminder that as digital tools become increasingly sophisticated at synthesizing personal information for commercial gain, the potential for catastrophic failure in data management practices grows proportionally, placing the privacy and safety of millions at stake.
⚖ The Balanced View
Supporting view
ClarityCheck argues the data was not 'publicly exposed' because it was stored in non-indexed, unlisted locations that were not discoverable through general internet searches or standard user interactions with their platform.
Concerns & criticism
Security experts and the broader industry define 'exposure' as any data accessible without authentication, noting that the company's lack of password protection left sensitive biometric and contact data reachable by anyone with the correct URL.
→What's next
ClarityCheck has officially committed to enhancing its security disclosure protocols to facilitate better communication with independent researchers in the future. It remains to be seen if regulatory bodies will launch formal investigations into the company's handling of biometric facial imagery and the systemic vulnerability of its stored data.































































































































































































































