Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Data Protection - A reverse image search platform exposed more than 9 million facial images
Data Protection Articles Latest News News & Analysis Threats and Vulnerabilities

A reverse image search platform exposed more than 9 million facial images

Kirsten DoyleBy Kirsten DoyleAugust 24, 20266 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
reverse image search
Share
Facebook Twitter LinkedIn Email Copy Link
AI Summary

A publicly accessible database linked to reverse image search service ClarityCheck exposed more than nine million images, including photographs of adults, teenagers, and children.

Fowler said the images he reviewed included profile pictures, screenshots, and physical photographs that appeared to have been uploaded for reverse image searches or identity verification. “I recently discovered a publicly exposed database that was neither password-protected nor encrypted,” Fowler said. “The database contained approximately 9,042,977 image files totaling 450.2GB of data.”.

In a reverse image search, the photograph itself can be used to find other information about the person pictured. “Facial images are fundamentally different from many other types of personal data because the face itself is the identifying characteristic and is used as a search key,” Fowler said.

Basic summary
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

A publicly accessible database linked to reverse image search service ClarityCheck exposed more than nine million images, including photographs of adults, teenagers, and children.

Cybersecurity researcher Jeremiah Fowler discovered the database, which was neither password-protected nor encrypted. It contained approximately 9,042,977 image files, amounting to 450.2GB of data. Most were stored in folders labeled “faces” and “profiles.”

Fowler said the images he reviewed included profile pictures, screenshots, and physical photographs that appeared to have been uploaded for reverse image searches or identity verification.

“I recently discovered a publicly exposed database that was neither password-protected nor encrypted,” Fowler said. “The database contained approximately 9,042,977 image files totaling 450.2GB of data.”

His investigation linked the files to ClarityCheck, a US-registered company that offers an online investigation service using reverse image search. Fowler found the cloud storage database URL in the source code of a public page. He could not determine whether ClarityCheck managed the database directly or whether a third-party contractor was responsible for it.

Fowler sent a responsible disclosure notice to ClarityCheck, and the database was subsequently restricted from public access. The company replied to thank him for reporting the issue and said it had acted to protect users’ data and privacy.

It is not known how long the database was publicly accessible or whether anyone accessed the records before Fowler found them. He said an internal forensic investigation would be needed to determine whether the data had been downloaded by third parties.

Why facial images pose a particular privacy risk

A facial image does not need to have a name or email address attached to raise privacy concerns. In a reverse image search, the photograph itself can be used to find other information about the person pictured.

“Facial images are fundamentally different from many other types of personal data because the face itself is the identifying characteristic and is used as a search key,” Fowler said.

ClarityCheck says its service can help users identify people, detect catfishing, investigate suspicious online profiles, and carry out OSINT-based searches. Its website also states that its reverse image search can be used to find names, social profiles, and a person’s online presence.

At the same time, the company’s disclaimer says it does not provide facial recognition or identity verification and instructs users to upload only images they have the right to share.

Fowler said some of the images he saw may have come from social media and dating accounts, private profiles, screenshots, or physical photographs. In some cases, the people pictured may not have known that someone else had uploaded their image to the service.

The exposed database also contained images of children. Fowler said he reviewed only the records necessary to verify and document the exposure and did not download the data.

Images appeared to remain beyond the stated 14-day limit

ClarityCheck’s terms say images submitted for reverse image lookup are stored for 14 days before being automatically deleted.

Fowler found images in the exposed database with timestamps that exceeded that period. He said this raised questions about how the company’s retention policy was being applied and how uploaded images and consent were being managed.

The timestamps alone do not establish why those images remained in the database. But the finding puts the amount of biometric data being retained, and the length of time it was being kept, under scrutiny.

Exposed images could support impersonation and scams

A facial image on its own is generally not enough to steal someone’s identity. Fowler warned that it could become more useful to criminals when combined with information available elsewhere.

Someone could potentially identify the person in a photograph and use the image to create a fake social media profile. It could also be used in phishing messages or impersonation scams targeting the person’s friends, family members, or colleagues. An attacker would not necessarily need to identify the person at all and could instead use the photograph as a generic fake persona.

AI tools also make photographs easier to manipulate and analyse. Fowler pointed to the potential for large image collections to become useful for facial recognition, tracking, or surveillance as the technology develops.

He did not find evidence that this happened to the ClarityCheck images. Nor did he claim that criminals, data brokers, nation-states, or other third parties accessed the database. The concern is based on what could be done with an exposed collection of facial images, not evidence that the images were misused.

Facial data remains useful long after an exposure

Facial data presents a problem that passwords and payment card details do not: people cannot replace it after an incident.

“Once biometric facial data is exposed, individuals cannot simply reset or replace their faces in the same way they would change a password or credit card number,” Fowler said.

Advances in AI could also make old image collections more useful. Fowler noted that AI models can already match unlabeled facial images at scale without names or profile information attached to them. He warned that large image datasets could potentially be used to develop or improve facial recognition, tracking, and surveillance technologies.

Companies need to limit how much facial data they keep

Fowler advised organisations collecting facial images to treat them as sensitive information and protect them to the same standard as other forms of personally identifiable information.

Encryption, restriction of access via role-based restrictions, multi-factor authentication, and ensuring that image stores are not accessible from the Internet are some of his recommendations. Other methods include performing security evaluations and penetration testing to find vulnerabilities before the data is compromised.

He also urged companies to keep as little biometric data as possible and securely delete records when they are no longer needed. Where possible, organisations should avoid retaining raw facial images.

Those who suspect that their facial images have been stored or used without their consent must inform the organisation that holds such images and the respective social networking site. According to Fowler, those people must notify the relevant privacy or data protection agency when necessary and inform their friends and relatives of any unusual messages or attempts at impersonation.

ClarityCheck had restricted access to the database by the time Fowler’s findings were published. It remains unknown how long the images were exposed or whether anyone else found them during that period.

Fowler stressed that he is not alleging wrongdoing by ClarityCheck or related entities. His investigation did not establish that the data was exploited or that any internal systems were compromised.

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    Post-DEF CON phishing campaign delivered AMOS and NetSupport malware
  • Kirsten Doyle
    AI agents taking unsanctioned action during cyber testing
  • Kirsten Doyle
    Expert panel: AI is writing the code. Who is defending it?
  • Kirsten Doyle
    One-click Claude Desktop flaw could enable hidden prompt injection and code execution

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}