Cybersecurity researcher Jeremiah Fowler discovered an unsecured Amazon S3 bucket containing nine million facial images linked to the people-search service ClarityCheck, raising significant privacy and security concerns.
Key Points
- Cybersecurity researcher Jeremiah Fowler identified 450 gigabytes of exposed data, including profile images and screenshots, stored in an unsecured Amazon S3 bucket.
- ClarityCheck allows users to identify individuals using photos, phone numbers, or email addresses by leveraging public records and open-source intelligence.
- The exposed database contained images of individuals who may not have consented to their photos being uploaded or stored by the service.
- Fowler warned that the exposed images could be harvested by AI bots for training purposes or exploited by malicious actors and data brokers.
- ClarityCheck disputes the findings, claiming the data was not publicly exposed because access required knowledge of a specific, unindexed URL.