Another week, another company hands your personal information to the open internet. This time it is ClarityCheck, a people-search tool that lets a stranger upload a photo of your face and pull up your name and social profiles. And this time the leaked data is not a number you can change. It is your face.
Independent security researcher Jeremiah Fowler found more than 9 million image files, roughly 450 GB, sitting in a cloud storage bucket that required no password to access. The folders were named "faces" and "profiles." The photos included adults, teenagers, and children. Many of the people in them never used ClarityCheck and have no idea they were ever in it.
What Happened
ClarityCheck stored uploaded images in an Amazon S3 bucket with no authentication on it. The URL to that bucket was sitting in the website's own publicly available source code. Anyone who looked could find it, and anyone who found it could pull down the contents.
A second misconfiguration exposed a separate set of data: email addresses, phone numbers, and other personal information belonging to the people who used the service.
Fowler reported the exposure to ClarityCheck and the bucket was locked down. The company's response is worth reading closely. It disputes that the data was "exposed" at all, arguing that an ordinary member of the public would not have stumbled onto it because the URL was not indexed by search engines. In other words, the lock was off the door, but the door was around the side of the building, so it does not count.
That is not how this works. An unsecured storage bucket is one of the most common things automated scanners hunt for. Researchers find them. Criminals find them faster. Nobody can say how long that bucket sat open or who else pulled from it before Fowler did.
What Was Exposed
According to the findings reported by Wired and confirmed across multiple outlets, the exposed data included:
- More than 9 million image files, including profile photos, screenshots, and other pictures of people's faces
- Images of adults, teenagers, and children
- Email addresses and phone numbers of ClarityCheck users, from a second misconfigured system
- Additional personal details tied to those accounts
Pay attention to what sits at the top of that list. A password gets changed in thirty seconds. A credit card gets reissued in a week. A driver's license number takes a trip to the DMV. Your face does not get reissued. Once a clean, labeled photo of you is in circulation alongside your name and your social media handles, it is usable for the rest of your life.
Who Is Affected
Two groups, and neither one signed up for this.
The first is anyone who uploaded a photo to ClarityCheck. Their email addresses and phone numbers were left in the open.
The second group is much larger and far more troubling: the people in the photos. ClarityCheck's whole business is letting one person upload a picture of someone else and identify them. The service asks users to check a box confirming they have permission to upload the image. A checkbox does not stop anyone from lying. That means the 9 million files are, in large part, pictures of people who never consented to being searched, never heard of the company, and never had any say in how their image was stored.
If someone has ever taken your photo off a social media account, a news article, a dating profile, or a company website and run it through a tool like this, you may be in that bucket. You have no way to check.
Here Is the Real Problem
A people-search site is not a bystander in the privacy problem. It is the problem. These companies exist to take scattered pieces of your identity and stitch them together into a single, searchable record. ClarityCheck's marketing pitch is that you can identify anyone from a single photo. That is the product. The breach did not create a new risk so much as it removed the paywall from a risk that already existed.
Now consider what a criminal does with a labeled face. A stolen photo paired with a name and social profiles is the raw material for a fake identity that survives scrutiny. It is what makes a romance scam profile look real. It is what makes a fake LinkedIn recruiter believable. It is what lets someone impersonate you to your own family. And with AI image and video tools, a few clean photos of a face are enough to generate new pictures, or a moving video, of that person saying and doing things they never did.
Then the second wave arrives. Data brokers scrape and cross-reference whatever surfaces. A face and a name get matched to a current address, a phone number, relatives, and daily patterns. A criminal with your photo has a template. A criminal with your photo and your home address has a plan.
You cannot un-leak the ClarityCheck data. You can shut down the machine that multiplies it.
What to Do Now
Whether or not you ever touched ClarityCheck, assume your face is already searchable and act accordingly:
- Audit what is public. Lock down social media privacy settings so profile photos are not visible to strangers. Think hard before posting clear, front-facing photos of your children anywhere public.
- Treat unexpected contact as hostile. Anyone who reaches out claiming to know you, work with you, or be related to you, and who can produce a photo to prove it, has not proven anything. Verify through a channel you control before you respond.
- Never upload a stranger's photo to a lookup tool, and think twice before uploading your own. You have no control over how long it is stored or how well it is secured. This story is the answer to that question.
- Get your data off the broker networks. A leaked face becomes dangerous when it is linked to your address, your phone number, and your relatives. Removing yourself from those networks cuts the supply line that turns a stolen photo into a working identity kit.
The People Already Protected Saw This Coming
Patriot Protect members are not scrambling today. They are already being scrubbed from the people-search and data broker networks that turn a leaked photo into a full profile, and the ones on monitoring tiers get alerted when their information turns up where it does not belong.
A company built to identify strangers from their faces left 9 million faces open on the internet, then argued it did not count. Breaches are not rare events anymore. They are the weather. The only question that matters is whether your information is sitting exposed and waiting, or actively being removed and watched.
Find out what is already out there about you. Run a free exposure scan and see exactly where your information is showing up.
