Cybersecurity researcher Jeremiah Fowler has uncovered a major data exposure involving millions of facial images from what appears to be a reverse image search service.

The findings were shared with ExpressVPN as part of an effort to raise awareness about online privacy and security risks.

Fowler discovered a publicly accessible database that was not protected by a password or encryption. The database contained approximately 9,042,977 image files totaling around 450.2GB. Most of the exposed files were stored in folders labeled “faces” and “profiles.”

A limited review of the database showed images of adults, teenagers, and children. The exposed material included profile pictures, screenshots, and physical photographs that appeared to have been uploaded for reverse image searches or identity verification purposes.

Further investigation linked the files to ClarityCheck, a U.S.-registered company that provides an online digital investigation service using reverse image search technology. The service says it can help users identify individuals, investigate suspicious profiles, detect catfishing, and perform OSINT-based identity verification.

The database was exposed through a cloud storage URL that was visible in publicly accessible page source data. However, it remains unclear whether ClarityCheck directly owned and managed the storage or whether a third-party contractor was responsible for it.

After discovering the exposure, Fowler sent a responsible disclosure notice to ClarityCheck. The company subsequently restricted access to the database, which was no longer publicly accessible when the findings were published. ClarityCheck thanked the researcher for reporting the issue and acknowledged the privacy concerns associated with the exposed images.

READ
Critical GitLab Flaw Could Let Attackers Delete Public Projects

It is still unknown how long the database had been publicly accessible or whether unauthorized individuals accessed or downloaded the information. Determining whether additional access occurred would require an internal forensic investigation.

The exposure raises particular concerns because facial images are biometric information. Unlike passwords or credit card numbers, a person’s face cannot simply be replaced after being exposed. Even when an image is not stored alongside a person’s name or email address, the face itself can act as an identifying characteristic.

The risks can become greater when exposed images are combined with other publicly available information. Fowler noted that such images could potentially be used to create convincing fake social media accounts, impersonate individuals, or make phishing and scam attempts appear more credible. These scenarios are described as potential risks rather than evidence that the exposed ClarityCheck images were actually misused.

ClarityCheck’s website states that it does not provide facial recognition or identity verification and tells users to upload only images they have the right to share. At the same time, its service description says its reverse image search can be used to identify people in photographs and find names, social profiles, and online presence.

The company’s terms also state that users must have the legal right to upload images and that submitted images are temporarily stored for 14 days before being automatically deleted. Fowler said he observed images in the exposed database with timestamps older than that period, raising questions about data retention and oversight.

READ
Sakura Internet Data Breach May Affect 1.36 Million Accounts

Some of the images may have originated from third-party sources, including social media accounts, dating applications, private profiles, screenshots, and physical photographs. This creates the possibility that some people pictured in the database may not have known their images were being collected, indexed, or stored through the service.

The exposure also highlights broader concerns about the growing availability of artificial intelligence tools capable of analyzing and manipulating facial images. Publicly available photographs can potentially be used in impersonation scams, fake profiles, phishing campaigns, and other forms of misuse.

Facial data also presents long-term privacy concerns because biometric information is persistent. Someone can change a password or replace a credit card after a breach, but they cannot change their face. As facial recognition, identity authentication, and AI-based image analysis continue to improve, large collections of exposed facial images could become increasingly valuable for tracking, identification, or surveillance technologies.

Fowler advised people who believe their facial images are being used without permission to report the issue to the organization responsible for collecting or storing the images, the relevant online platform, and their local privacy or data protection authority where applicable. He also recommended warning family members, friends, and business contacts about possible impersonation attempts or suspicious messages involving their image.

For organizations handling biometric information, Fowler recommends treating facial images as sensitive data and protecting them with strong security controls. This includes encryption, role-based access restrictions, multi-factor authentication, regular security assessments, and penetration testing. Companies should also ensure that stored images cannot be accessed publicly.

READ
Hackers Are Exploiting a macOS Screen Sharing Flaw to Install Crypto Miners

Organizations should minimize the amount of biometric information they retain, securely delete data that is no longer required, and avoid keeping raw facial images whenever possible. Employees and contractors should also receive security awareness training covering phishing, social engineering, and insider threats.


Buy ExpressVPN with PayPal or Credit Card

Fowler said he did not download the exposed database. As part of his ethical research process, he reviewed only a limited number of records needed to confirm the exposure and responsibly notified the relevant organization.

The researcher also emphasized that the discovery does not establish wrongdoing by ClarityCheck, Clarity Check Ltd., or related entities, and there is no claim that the exposed information was actively exploited or that ClarityCheck’s internal systems were compromised. The potential misuse scenarios described in the report are intended to highlight privacy and security risks associated with exposed biometric information.

Advertisement