Security researcher Jeremiah Fowler found more than 9 million image files — roughly 450GB — belonging to ClarityCheck, a reverse-lookup service that advertises face search as private and secure, sitting in an unsecured Amazon S3 bucket. Files were organised in folders named “faces” and “profiles”, and the bucket’s URL appeared in the service’s own publicly available website code. A second misconfiguration exposed email addresses and phone numbers.
The images include what appear to be profile photos, screenshots and photographs of adults, teenagers and children. Fowler reports the store was likely exposed for months, that his earlier notifications received no response, and that access was restricted only after a journalist contacted the company in July. Whether anyone malicious found it first is unknown and probably unknowable.
Nobody In The Bucket Is A Customer
A face-search service works by indexing images of people who never signed up for anything. The population in the bucket has no account to close, no password to change and no relationship to end — the position the corpus set out at 26-0111 for broker datasets generally. Most of the nine million will never learn they were in it, because no mechanism exists that could tell them.
A Face Is The Field That Cannot Be Rotated
The corpus drew the line at 26-0324: reissuance separates recoverable exposure from permanent. A face sits on the wrong side of it. Nine million images, organised for matching and exposed together, are useful input to exactly the kind of recognition tooling the service itself sells — and a person whose photo was in the store in 2026 will have the same face in 2046.
The Gap Between The Promise And The ACL
The service marketed its search as private and secure while the store behind it was readable by anyone who looked at the page source. No intrusion was required and none is alleged; the mechanism is a permission setting. The months of silence to a researcher, ended within weeks of a press inquiry, describe where the incentive to fix actually came from — and it was coverage, a regulator’s attention arriving second-hand.
Compiled from the researcher’s published findings and reporting of them, listed below. The company has not published its own account, and no confirmation of malicious access exists in either direction. Image counts and the exposure window are the researcher’s. Graded medium. Corrections: corrections@forensicpost.com.