Nine Million Photos of People’s Face Discovered in Exposed Database

2 hours ago 12
A collage of many individual portraits and group photos, all with the faces of the people obscured by black rectangles.A tiny sample of the nine million photos found in the unsecured bucket. | Photo via Jeremiah Fowler / ExpressVPN

A website that helps to identify people using just a photo was found to have a massive database of images unsecured on the web.

ClarityCheck offers users the chance to look up people via a phone number, email, or photo by uploading one piece of information; it then searches for more info using public records and OSINT.

But cybersecurity researcher Jeremiah Fowler recently discovered an exposed cache of nine million image files of people’s faces.

The data, which totaled 450 gigabytes, was made up of profile images, screenshots, and photographs. Fowler found it in an unsecured Amazon S3 bucket.

While ClarityCheck’s terms and conditions require users to have permission from the people in the photos when they upload, Fowler tells Wired that, in practice, there may be people in the exposed database who had no idea that their image had been uploaded to ClarityCheck.

“If you’re trying to find out who a person is, you might not have authorization or permission, so people might not know that their image had been dumped into this database that was public,” Fowler says. “An AI bot could crawl it, extract faces, and use them for training. And there are lots of pictures of kids in there.”

Fowler sent ClarityCheck a disclosure notice alerting them to the exposed data, which he says was accessible to anyone with an internet connection.

However, the company refutes the notion that the data was “exposed”, insisting to Wired that no “ordinary member of the public” could access it.

“We do not accept that data in the temporary storage location was ‘publicly exposed,’ which implies large-scale public access,” a spokesperson says. “Access required knowledge of a specific, unindexed URL that was not discoverable through ordinary use of the ClarityCheck service or a general web search.”

While Fowler does not claim that the photos were accessed by any third parties, he does want to highlight the risk that images uploaded to ClarityCheck could be used for unintended purposes.

“Once data is exposed in a breach, there is a possibility it could also be accessed and used by data brokers, criminals, or even nation-states without the knowledge of the individual or the organization responsible for collecting and storing the data,” he writes for the ExpressVPN blog.

“As a general rule, companies should minimize the amount of biometric data they retain, securely delete records that are no longer needed, and avoid storing raw facial images whenever possible.”

Photos can be used by scammers: earlier this week, PetaPixel reported on criminals who exploit vacation photos posted to social media and use them to target victims.

Affiliate Disclosure PetaPixel articles may include affiliate links; we may earn a commission if you buy through one.

Read Entire Article