The ClarityCheck facial data leak reportedly exposed a database containing more than nine million facial images. The collection allegedly included photographs of children and teenagers, raising serious privacy and surveillance concerns.

Security researcher Jeremiah Fowler said the database held around 450GB of data. He found it online without password protection or encryption, according to his report.

ClarityCheck disputes that the information was publicly exposed.

Database reportedly contained images from online sources

ClarityCheck offers reverse-lookup tools designed to help users identify callers, check contacts and research people online. Fowler said the exposed database contained facial images collected from sources such as social media platforms and dating sites.

Many of the people shown may not have known that the service held their images. A person could potentially enter the database after another user uploaded a photo to search for them.

The reported collection included more than facial photos. It may also have contained related profile data, although the full scope of the records remains unclear.

Questions raised over image retention

ClarityCheck told users that it would automatically delete uploaded images after 14 days. However, Fowler said he found files with timestamps that appeared to exceed that period.

That finding raises questions about consent, data retention and oversight. It also remains unknown how long the database was accessible online.

Fowler said he could not confirm whether ClarityCheck directly managed the exposed storage or used an external provider.

Why exposed facial images pose lasting risks

A leaked password can be changed. Facial data cannot.

Large image collections could attract criminals seeking material for impersonation scams, deepfakes or identity fraud. They could also interest organisations developing facial-recognition, tracking or surveillance technology.

The risks are particularly serious when databases contain photographs of children. Criminals may misuse those images to create harmful manipulated content.

AI systems can already match faces at scale, even when the images lack names or profile details. As a result, an exposed facial dataset may create risks that continue long after the initial incident.

How to check whether ClarityCheck holds your image

It is difficult to confirm whether your image appeared in the reported ClarityCheck database. Traditional data-breach checkers can search email addresses, phone numbers and passwords, but they cannot reliably search facial images.

Searching for yourself through a reverse-image service may not provide a clear answer. It could also require you to upload a fresh image of your face.

People in the UK or EU can instead consider submitting a data access request under privacy law. They can ask ClarityCheck whether it holds, or previously held, an image of them and request details about the source of that image.

Useful questions include whether the company stored an image in its faces or profiles databases, whether an image appeared in the exposed dataset, and which account uploaded it.

ClarityCheck disputes exposure claim

ClarityCheck challenged the report’s description of the incident as a public exposure. The company argued that the database required an unindexed web address, rather than appearing in search results.

However, Fowler said the storage required no login or other authentication. He also said he located the address by reviewing the service’s code.

The ClarityCheck facial data leak highlights the limits of treating obscure web links as a security measure. If sensitive biometric data remains accessible without authentication, it can still create major privacy risks.


0 responses to “ClarityCheck Facial Data Leak Exposes 9 Million Images”