9M Images Exposed by Facial Recognition Platform

9,042,977 images totaling 450.2 gigabytes of data were exposed in a public database with no password protection or encryption. Facial images of adults, teenagers and children were accessible. These included:
- Profile pictures
- Screenshots
- Physical photographs
The files belonged to ClarityCheck, a digital investigation service leveraging reverse image search for OSINT-based identity verification. Upon discovery of the exposed database, Cybersecurity Researcher Jeremiah Fowler reached out with a responsible disclosure notice. The organization expressed gratitude for the notice and the database was restricted from public access.
This could be a considerable privacy concern. As risks of impersonation grow more complex, especially with the proliferation of AI deepfakes, the exposure of facial imagery on such a wide scale could have posed a cyber threat. The exposure of children's faces could be especially concerning, as recent events have shown cybercriminals creating AI-generated child abuse images (CSAM) of students in order to extort schools.
However, as Fowler points out there is no evidence any malicious actor accessed the database nor exploited its contents, all discussions of possible ramifications are purely hypothetical. Nevertheless, in the event such information was placed into the hands of malicious actors, the consequences of such a leak could be significant.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!







