ClarityCheck Called Its Face Search “Private and Secure.” Then 9 Million Photos Leaked.

Researcher Jeremiah Fowler found 9 million faces in a password-free Amazon S3 bucket, including images of minors

Nikshep Myle Avatar
Nikshep Myle Avatar

By

Image: Deposit Photos

Key Takeaways

Key Takeaways

  • Discover how 9 million facial photos sat unprotected in ClarityCheck’s unsecured Amazon S3 bucket.
  • Recognize ClarityCheck’s “private and secure” claims collapsed when a URL in public code exposed all data.
  • Understand that most victims never consented — others uploaded their faces without their knowledge.

A user uploads a photo of someone to verify that person’s identity. ClarityCheck promises the process is “private and secure.” What actually happened was that upload — and roughly 9 million others — sat in an Amazon S3 database leak with no password, no authentication, nothing. Security researcher Jeremiah Fowler found the unsecured cloud storage bucket. The folders were literally named “faces” and “profiles.” No sophisticated hacking required. The bucket’s URL was embedded directly in ClarityCheck’s own public website code.

That’s not a breach. That’s leaving your diary on the bus with your name on the cover.

The 450 GB dataset included adults, teenagers, and children. A second vulnerability let anyone manipulate URL strings in a standard browser to pull names, physical addresses, phone numbers, and email addresses tied to specific people. Fowler spent months trying to tell ClarityCheck about both issues — and received no response until a journalist intervened.

“An AI bot could crawl it, extract faces, and use them for training. And there are lots of pictures of kids in there,” Fowler told WIRED, which broke the story in August 2026 after the company finally locked down access following a journalist’s inquiry in July.

The downstream threat isn’t abstract. Fowler noted that scammers could scroll the bucket, pick attractive photos, and feed them into AI tools to build convincing fake personas for romance scams and catfishing. Think of it as a self-service fraud kit, pre-loaded with real human faces.

“Not Publicly Exposed” – ClarityCheck’s Semantic Dodge

ClarityCheck’s official response disputed the characterization that its data was publicly exposed — a position the security community flatly rejected.

The company argued that an ordinary user wouldn’t encounter the unindexed URL through normal browsing. Mark Beare, head of consumer products at Malwarebytes, countered directly: industry standards and US federal guidance define exposure as any unauthenticated, internet-reachable access — whether or not anyone exploited it. The months of silence before a journalist’s call made that distinction largely academic.

Rebecca Williams, director of strategy for privacy and data governance at the ACLU, identified the deeper problem. Platforms built on biometric data collection “will continue to carry these risks,” she noted, “because the model itself depends on collecting sensitive data.” This isn’t really a misconfiguration story. It’s a business model story — one echoed by the rise of the surveillance app as a tool of covert identity tracking.

A WIRED reporter tested ClarityCheck‘s system using their own photo and received a correct identification, a full biography, and multiple matched images pulled from across the web. The facial recognition pipeline works. The security protecting everything it processed did not.

Most people in that bucket never uploaded their own photo. Someone else uploaded them — without consent, without knowledge — to identify them. Their faces are now part of a dataset they cannot opt out of, cannot change, and cannot take back. ClarityCheck’s terms and conditions do not cover that part — nor do they address what happens when systems are caught secretly tracking users without their knowledge.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →