Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Aug 23, 2026 · 6 min read

9 Million Face Photos Leaked by a “Private” Search Tool

Security researcher Jeremiah Fowler found 9,042,977 image files, 450.2 GB in all, in an unsecured cloud bucket owned by ClarityCheck, a US registered reverse face search service. It was not locked until WIRED contacted the company in July 2026, and most of the people in the photographs had never used the site.

A company whose entire business is telling you who a stranger in a photograph really is left nine million photographs of strangers on the open internet, in a folder called "faces", with no password on it.

Key Takeaways

  • Jeremiah Fowler found 9,042,977 image files totalling 450.2 GB in an unsecured cloud bucket belonging to ClarityCheck, a US registered reverse face search service.
  • The files sat in folders named "faces" and "profiles", needed no authentication, and were reachable through a storage URL printed in ClarityCheck's own website code.
  • Fowler's sample held images of adults, teenagers and children pulled from private social accounts, dating profiles and screenshots, so most of the people depicted never used the service.
  • A separate misconfiguration let anyone alter a ClarityCheck web address, enter a name, and surface candidate email addresses, phone numbers and physical addresses.
  • ClarityCheck restricted the image store only after WIRED contacted the company in July 2026, and disputes that the data was publicly exposed because the URL was unindexed.

What Happened to ClarityCheck's Face Database?

ClarityCheck left a cloud storage bucket holding 9,042,977 image files, 450.2 GB in total, publicly readable with no password and no encryption. Fowler published the finding on 19 August 2026, and Malwarebytes and other outlets picked it up the same week.

Two details make this more than an ordinary leaky bucket. The folder structure was self documenting: "faces" and "profiles". And the address was neither guessed nor brute forced. It was printed in the page source of ClarityCheck's own website, so the barrier between a curious visitor and nine million faces was View Source.

Do the arithmetic and the contents come into focus. 450.2 GB across 9,042,977 files averages roughly 52 KB per image. That is not the footprint of high resolution camera captures. It is the footprint of compressed web images: profile thumbnails, screenshots, pictures lifted off a dating app.

Was Your Face in There if You Never Used the Service?

Quite possibly, and that is the structural problem with the whole people finder category. ClarityCheck sells reverse image search to people who want to identify someone else, usually a dating app match. Fowler put the consent gap plainly: people do not typically upload photos to identify themselves or people they already know.

The uploader consents. The person in the photograph does not, is not told, and has no practical way to find out. ClarityCheck's terms require the uploader to affirm a legal right to the image, an obligation Fowler calls functionally unenforceable, and promise uploads are deleted after fourteen days. Fowler saw timestamps older than that.

Set this beside the closest comparison. Clearview AI became a global regulatory case over roughly 60 billion scraped images, drawing €30.5 million from the Dutch data protection authority alone. ClarityCheck's store is 0.015% of that size. But Clearview's scandal was the collection. Here the collection happened and the lock was missing too.

A leaning stack of unsorted printed photographs turned face down beside an open metal filing drawer in a dim records archive room

What Else Was Exposed Besides the Photos?

Contact information, through a second and unrelated weakness. Reporting on the incident found that modifying certain ClarityCheck web addresses and entering a name would surface candidate email addresses, phone numbers and physical addresses, with no authentication involved.

Be precise about the boundary, because early roundups blurred it. The bucket held images. The names, emails and phone numbers came from a separate misconfiguration in the lookup interface. Both were open. They were not the same hole.

What stays unverified is the question that matters most: whether anyone else found either one first. There were no public access logs, so nobody can establish whether the images were pulled in bulk. Fowler states he implies no wrongdoing by ClarityCheck and saw no evidence of an internal compromise.

Why Is Leaked Biometric Data Different?

Because a face cannot be rotated. Fowler's framing is the one to keep: once biometric facial data is exposed, people cannot reset or replace their faces the way they change a password. Biometric Update flagged the fraud risk, and it is not abstract. Fowler described a scammer browsing the bucket, picking attractive photographs, and feeding them into generative tools to build synthetic personas for romance fraud.

Note the circularity. ClarityCheck markets itself as protection against catfishing, and its exposed store is close to an ideal raw material supply for the next generation of it.

The regulatory picture is thinner than you would hope. Biometric claims in the US still lean on Illinois BIPA, the statute behind the class actions filed against Whoop and Oura this year. A face scraped from a dating profile by a company with no relationship to the person depicted fits awkwardly into a law drafted around employers and fingerprint time clocks.

What This Means for Your Inbox

The email addresses and phone numbers surfaced by that second flaw are the part of this story that lands in your inbox. An address harvested from an open lookup endpoint does not stay put. It becomes a line in a list, and the list gets sold and merged, which is how a storage misconfiguration ends up as targeted phishing that already knows your name and your city. Our coverage of the Washington attorney general's data broker findings traces the same pipeline at state scale.

The consent logic is familiar too. A people finder holds an image of you because someone else uploaded it, and you were never told. A tracking pixel in a marketing email records that you opened it, roughly from where and on what device, because a sender embedded it, and you were never told either. Identical shape: the data about you is generated by a transaction between two other parties.

How Do You Get Yourself Out of Face Search Tools?

You cannot get out completely, but you can shrink the surface. Concrete steps, in rising order of effort:

  • File one deletion request through California's DROP. The state data broker registry lists 581 brokers, and one free request reaches all of them, with $200 a day per ignored request behind it since August. The limit: it binds only registered brokers, and services calling themselves search tools may never appear there.
  • Reverse search your own photographs. Run your main profile picture through the reverse image search in major search engines. If it comes back on dating or aggregator sites, you have a target list.
  • Lock down the sources. Set social and dating profiles so photos are visible to connections only, and strip your face from public avatars on forums. Scrapers take what is reachable.
  • Send removal requests directly. Most people finder services run an opt out form because registration law requires one. Use it on each site you found and keep the confirmation.
  • Watch for downstream fraud, not the leak. The FTC's IdentityTheft.gov is the free starting point if unauthorised accounts or credit activity appear.

The 450 GB in that bucket was, by ClarityCheck's own published policy, supposed to have been erased a fortnight after upload. A retention promise that lives only in a terms page is not a control. It is marketing copy, and this is what the difference costs.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.