AUTO-UPDATED

Nine Million Photos of People’s Faces Discovered in Exposed Database

Cybersecurity researcher Jeremiah Fowler discovered an unsecured Amazon S3 bucket containing nine million facial images linked to the people-search service ClarityCheck, raising significant privacy and security concerns.

Key Points

  • Cybersecurity researcher Jeremiah Fowler identified 450 gigabytes of exposed data, including profile images and screenshots, stored in an unsecured Amazon S3 bucket.
  • ClarityCheck allows users to identify individuals using photos, phone numbers, or email addresses by leveraging public records and open-source intelligence.
  • The exposed database contained images of individuals who may not have consented to their photos being uploaded or stored by the service.
  • Fowler warned that the exposed images could be harvested by AI bots for training purposes or exploited by malicious actors and data brokers.
  • ClarityCheck disputes the findings, claiming the data was not publicly exposed because access required knowledge of a specific, unindexed URL.

Why it Matters

This incident highlights the growing risks associated with the collection and storage of biometric data by third-party search services. It underscores the potential for unauthorized access to sensitive personal imagery, which could be exploited for identity theft, scams, or unauthorized AI model training.
PetaPixel Published by Matt Growcoot
Read original