Facial recognition vault exposed 9M images
An open database from ClarityCheck exposed 9M+ facial images, risking identity theft and phishing.
A US-based identity verification service left a database holding more than nine million facial images exposed to the open internet, according to a cybersecurity researcher who found the misconfigured storage. The leak included profile pictures, screenshots, and scans of physical photographs, raising concerns about identity theft and phishing.
Researcher stumbles on exposed archive
Jeremiah Fowler, a cybersecurity researcher known for hunting exposed databases, discovered the unprotected database, which was 450.2GB in size. It contained exactly 9,042,977 image files, all seemingly uploaded by users of the service. The images showed adults, teenagers, and even children, and were stored in folders labeled “faces” and “profiles”.
The database belonged to a company called ClarityCheck, a US-registered firm that describes itself as a “reverse phone, email, image, vehicle lookup”. The service allows users to identify unknown callers, verify online contacts, check photos, and decode vehicles using publicly available data from “trusted sources”.
Fowler's discovery is notable because it involved not just metadata or text records, but actual visual representations of people's faces, making the potential for misuse more direct than a typical credential leak.
Legitimate tool, serious risk
ClarityCheck is a legitimate business whose use case has grown more important as cybercriminals create fake internet personas daily, using them in schemes from romance scams to fake job offers. To do that, they will steal other people's photos, obtain them on the dark web, or generate them using artificial intelligence.
Being able to verify someone's identity has become essential due diligence for both personal and business matters. The exposure of a verification service's own data undermines the trust that such a service is supposed to provide.
The leaked images—profile pictures, screenshots, and scans of physical photographs—could be used to create convincing fake profiles or to target individuals with phishing attacks that reference their actual appearance.
Company responds quickly
As soon as Fowler confirmed who owned the database, he reached out to ClarityCheck and responsibly disclosed his findings. The company responded quickly, barring further access and thanking the researcher for his work.
I completely understand your concerns regarding the exposure of sensitive images and the associated privacy risks. We greatly appreciate ethical researchers like you who bring these matters to our attention so we can act swiftly to protect our users' data and privacy.
— Representative of ClarityCheck, as quoted by Jeremiah Fowler
Unfortunately, without a deeper investigation on ClarityCheck's end, there is no way of confirming exactly how long the database remained open, or if anyone accessed it before. So far, there is no evidence of abuse, since a “ClarityCheck photo database” is currently not being distributed or sold anywhere on the dark web.
Misconfigured databases: a recurring problem
This incident is the latest in a long line of exposures caused by misconfigured databases. In a world where data theft and leaks are increasingly common, the cause that's easiest to address is also the one resulting in the most exposures. Almost every business harvests and stores data about employees, partners, and customers, often in cloud databases for easier access and integration with business intelligence software.
Cloud service providers operate on a “shared responsibility model”, meaning they are responsible for providing industry-standard security features, while users are responsible for using those features and properly configuring their databases—namely, setting up a strong password or encrypting the content. However, many organizations don't seem to be aware of this model, believing it's the service provider's task to keep data safe. Others simply leave archives accessible by mistake.
Fowler and other researchers have found dozens of enormous databases that leaked sensitive data on hundreds of millions of people. In 2026, researchers found that European cloud provider Nextcloud kept an unprotected database on the public internet, containing 367,000 records (8GB) of sensitive employee and client data. In 2025, IMDataCenter, a Florida-based data hygiene, enhancement, and append services provider, was leaking 38GB of sensitive personal records, with 10,820 records in total. In 2024, sports analytics technology company TrackMan exposed sensitive customer data: 110TB and 31,602,260 records, with no password.
How criminals exploit exposed data
Criminals are aware of these misconfigurations and take advantage of them to steal valuable information. By using widely available tools like Shodan, Censys, or FOFA, they can scour the web for unencrypted, non-password protected databases and exfiltrate data to be used in phishing, business email compromise, and other forms of cyberattacks.
The exposure of facial images adds a particularly dangerous dimension, as these can be used to bypass facial recognition systems, create deepfakes, or run targeted social engineering campaigns. Even if the database was not accessed before ClarityCheck secured it, the very fact that it was publicly accessible for an unknown period means the risk cannot be fully ruled out.
What users should know
For those who may have used ClarityCheck's services, the incident raises questions about the safety of their personal data. While there is no confirmed evidence of misuse, the lack of clarity about the exposure window is concerning. Users should remain vigilant for unsolicited communications that might reference their photos or personal details.
- 9,042,977 image files exposed in total
- 450.2GB database size
- Folders labeled “faces” and “profiles”
Fowler's findings highlight the need for companies to understand their security responsibilities when storing sensitive data, especially in cloud environments. The shared responsibility model is not just a technicality; it is a critical framework for protecting user privacy.
Why it matters to you
This incident could mean that anyone who used ClarityCheck's services may have had their facial images exposed to potential criminals. Even with no evidence of dark web distribution so far, the risk of identity theft and phishing remains. For businesses, this is a reminder that even legitimate, well-intentioned services can become vectors for data breaches if their infrastructure is not properly secured. The fact that this database was left open for an unknown period suggests that the gap between security awareness and actual practice remains wide, and that a single misconfiguration can undo the trust that companies like ClarityCheck are built on.
Sources
- TechRadar Original source
Continue Reading
Android Banking Trojans Gain On-Device Fraud Tools
ToxicPanda 2.0 and GoldDigger expand targets with automated fraud and credential theft.
Citrix NetScaler flaws: patch gap may invite attackers
Citrix warns of two NetScaler flaws, including an auth bypass, urging immediate patches.
AI-Assisted Attacks Target Water Systems
US agencies warn hackers are exploiting Siemens PLCs in critical infrastructure with AI-generated scripts.