Desk live·
ForensicPost
Breaches/Exposure/File 26-0821

ClarityCheck Left 9 Million Face Images in an Open Bucket, Reachable From Its Own Site Code

A researcher found the face-search service’s S3 store — 450GB of photos of adults, teenagers and children — open to anyone with the URL, which sat in the site’s public code. Access was closed only after a journalist asked.

Constructed geometry · not a chart of case data
TargetPeople indexed by ClarityCheck
ActorUnattributed
D. Kennedy11 min readConfidence: medium3 sources reviewed

Security researcher Jeremiah Fowler found more than 9 million image files — roughly 450GB — belonging to ClarityCheck, a reverse-lookup service that advertises face search as private and secure, sitting in an unsecured Amazon S3 bucket. Files were organised in folders named “faces” and “profiles”, and the bucket’s URL appeared in the service’s own publicly available website code. A second misconfiguration exposed email addresses and phone numbers.

The images include what appear to be profile photos, screenshots and photographs of adults, teenagers and children. Fowler reports the store was likely exposed for months, that his earlier notifications received no response, and that access was restricted only after a journalist contacted the company in July. Whether anyone malicious found it first is unknown and probably unknowable.

Nobody In The Bucket Is A Customer

A face-search service works by indexing images of people who never signed up for anything. The population in the bucket has no account to close, no password to change and no relationship to end — the position the corpus set out at 26-0111 for broker datasets generally. Most of the nine million will never learn they were in it, because no mechanism exists that could tell them.

A Face Is The Field That Cannot Be Rotated

The corpus drew the line at 26-0324: reissuance separates recoverable exposure from permanent. A face sits on the wrong side of it. Nine million images, organised for matching and exposed together, are useful input to exactly the kind of recognition tooling the service itself sells — and a person whose photo was in the store in 2026 will have the same face in 2046.

The Gap Between The Promise And The ACL

The service marketed its search as private and secure while the store behind it was readable by anyone who looked at the page source. No intrusion was required and none is alleged; the mechanism is a permission setting. The months of silence to a researcher, ended within weeks of a press inquiry, describe where the incentive to fix actually came from — and it was coverage, a regulator’s attention arriving second-hand.

How we reported this

Compiled from the researcher’s published findings and reporting of them, listed below. The company has not published its own account, and no confirmation of malicious access exists in either direction. Image counts and the exposure window are the researcher’s. Graded medium. Corrections: corrections@forensicpost.com.

Sources
  1. 9 million images of people’s faces exposed by reverse lookup serviceMalwarebytes
  2. ClarityCheck data leak exposes 9M face imagesCybernews
  3. Nine Million Photos of People’s Faces Discovered in Exposed DatabasePetaPixel
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary