9 Million Face Photos Were Left Exposed by a Site That Promised Privacy. Protect Yours Now

You did not need a ClarityCheck account to appear in its unsecured database. Someone else could have uploaded your face without your knowledge.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

Your face could end up in a people-search database even if you never visited the site or agreed to be searched.

ClarityCheck, a reverse-lookup service that advertised its image searches as “private and secure,” left more than 9 million image files accessible online without authentication.[1]

The collection included photos of adults, teenagers, and children. Some of the people pictured may never have known that someone else uploaded their photos.

ClarityCheck has secured the database, and there is no public evidence that criminals downloaded it. However, the incident shows how little control you may have over where your face ends up online.

In this article
What ClarityCheck exposed
Someone else may have uploaded your face
How to protect your face online
Bottom line

What ClarityCheck exposed

Security researcher Jeremiah Fowler discovered a cloud database containing approximately 9,042,977 image files, totaling 450.2 GB.

The files appeared in folders labeled “faces” and “profiles.” Fowler’s limited review found profile pictures, screenshots, physical photographs, and other images of adults, teenagers, and children.

The database was stored in an Amazon S3 bucket that did not require a password or other authentication. Its address could be found in ClarityCheck’s publicly available website code.

ClarityCheck disputed that the files were “publicly exposed,” arguing that someone would need to know a specific, unindexed URL to access them. However, anyone who found that URL could reportedly view the files without signing in.

The 9 million figure represents image files, rather than 9 million confirmed victims. ClarityCheck said the database included duplicate, cropped, and resized versions of the same photos.

There is also no evidence that hackers stole the files or that ClarityCheck’s internal systems were breached. The company restricted access after being contacted about the findings.

Someone else may have uploaded your face

ClarityCheck allows users to upload a photo and search for information about the person shown.

The company requires uploaders to confirm that they have permission to share the image. That protection depends entirely on users telling the truth.

Someone could upload a screenshot from a dating profile, a social media picture, or even a scanned photograph. The person pictured may never know that ClarityCheck received or stored it.

When a WIRED reporter tested the service using their own face, the website said it was “scanning facial landmarks” and “mapping unique face geometry.” It offered a report that could include a name, addresses, location history, social media profiles, photos, videos, and “hidden dating profiles.”

A separate configuration problem also allowed ClarityCheck website addresses to be manipulated to reveal possible email addresses, phone numbers, and physical addresses associated with a name. The company secured that issue after being contacted.

Currently, there’s no indication that every exposed face was linked directly to contact information. Still, a real photo can help a scammer create convincing dating profiles, social media accounts, phishing messages, or impersonation schemes.

How to protect your face online

No public checker can confirm whether your photo appeared in the exposed database. That said, you can still reduce how easily strangers and people-search services can connect your face to your identity.

  1. Delete or suppress your ClarityCheck data: If you used the service, delete your account. You can also use its privacy center to request access, deletion, or suppression, even if you never created an account.
  2. Search for copies of your photos: Run your public profile pictures through Google Lens or TinEye, and search your name and usernames for unfamiliar profiles. Avoid uploading photos to unknown “free” lookup sites.
  3. Lock down public images: Review your social media and dating profile settings, remove abandoned accounts, and limit personal photos to trusted contacts. Parents should also check which pictures of their children are publicly visible.
  4. Prepare for impersonation scams: Create a family safe word for urgent requests involving money or account access, which can also help protect against AI voice-cloning scams.
  5. Document fake accounts: Save screenshots, usernames, profile links, messages, and timestamps before reporting an impersonator. If fraud or identity theft occurs, follow the recovery steps at IdentityTheft.gov.

Bottom line

ClarityCheck has restricted access to the exposed database, and no misuse has been confirmed. The larger privacy problem remains.

Someone else can upload your face to a service designed to identify you, potentially without your knowledge or permission. Reducing public photos, checking for impersonation, and requesting removal from people-search databases can help you regain some control.

Author Details
Thomas Kent is a multi-disciplined reporter with over a decade of experience covering online platforms, digital trends, and consumer-facing tech. Tom focuses on digital privacy, data tracking, and user behavior, with a particular interest in how cookies, online surveillance, and platform design shape the modern internet experience. His reporting takes a research-driven, news-focused approach, translating complex technical topics into clear, accessible insights.

Citations

[1] Reverse-lookup service exposed millions of photos of people’s faces