A major security misconfiguration at people-search tool ClarityCheck has left over 9 million image files, including facial photos, publicly accessible.

  • ClarityCheck's unsecured Amazon S3 bucket exposed 450 GB of data.
  • Over 9 million images, including faces of adults and children, were leaked.
  • Personal identifiers like email addresses and phone numbers were also compromised.

In a staggering blow to digital privacy, the people-search platform ClarityCheck has been caught leaving massive amounts of sensitive data exposed to the open internet. Independent security researcher Jeremiah Fowler discovered that the website's database contained more than 9 million image files, providing a direct window into the private lives of millions of users.

The breach involved an unsecured Amazon S3 bucket containing approximately 450 GB of data. The exposed files were organized into folders specifically named “faces” and “profiles,” making it alarmingly easy for anyone to locate and download photographs of adults, teenagers, and even children. This exposure was facilitated by a URL embedded within the company’s own publicly available website code.

Why This Matters

BozokMedia analysis shows that this incident highlights a systemic failure in how data-aggregation companies manage the vast amounts of personal information they harvest. While ClarityCheck markets its services as “private and secure,” the reality of its infrastructure suggests a catastrophic lack of basic security hygiene, turning a tool meant for identification into a tool for mass surveillance and potential identity theft.

The exposure of facial data is uniquely dangerous because, unlike a password, you cannot change your face once it is compromised.

ClarityCheck operates in the growing market of 'people-finder' tools, which claim to identify individuals using phone numbers, email addresses, vehicle identification numbers (VIN), and names. Their specialized photo-search feature promises to identify anyone in a photograph and find their social media profiles within seconds—a feature that, in this context, has become a liability for the very people it claims to assist.

Historical Background

The rise of people-search engines has been fueled by the massive digitization of public records and social media data. While these services offer convenience for locating lost contacts or verifying identities, they have created a centralized honeypot for hackers and bad actors, leading to a series of high-profile data leaks over the last decade.

Did You Know?: Cloud storage misconfigurations, like the one seen in the ClarityCheck case, are one of the leading causes of massive data breaches globally.

Frequently Asked Questions

1. What kind of data was exposed in the ClarityCheck leak?
The leak included over 9 million images (faces, profiles, screenshots), email addresses, and phone numbers.

2. How could anyone access this data?
The data was stored in an unsecured Amazon S3 bucket that could be accessed via a URL found in the company's public website code.