ClarityCheck exposed 9M photos of children and adults online — company denies data breach

ClarityCheck exposed 9M photos of children and adults online — company denies data breach

Independent security researcher Jeremiah Fowler has uncovered a massive data exposure involving ClarityCheck, a people-search service. The company left over 9 million image files publicly accessible, along with email addresses and phone numbers of its users, due to a misconfigured cloud storage bucket.

The exposed database contained approximately 450 GB of images, including profile pictures, screenshots, and other photos of adults, teenagers, and children. All files were stored in an unprotected Amazon S3 bucket, organized into folders labeled "faces" and "profiles." The storage was accessible to anyone online via a URL that was embedded in the public source code of the company's website. This meant that any individual with basic web development knowledge could potentially view and download the images.

ClarityCheck is a service that allows users to search the internet, open sources, and other databases to identify individuals. The platform's website states that searches can be performed using phone numbers, email addresses, vehicle identification numbers, and names. The service is designed for background checks and identity verification, but the exposed data included sensitive personal information of people who may have never consented to being listed.

The company has since secured the database, but Fowler warns that it appears to have been publicly accessible for several months. His attempts to report the issue to ClarityCheck were unsuccessful, raising concerns about the company's security practices and responsiveness. Although the website requires users to confirm they have permission to upload photos, Fowler notes that those whose images ended up in the database may have been completely unaware of their inclusion.

A representative for ClarityCheck denied the claims of a data breach, arguing that an "ordinary citizen" would not have been able to access the data because it required knowledge of a specific, non-public URL. However, Fowler countered that the URL was embedded in the site's public source code, making it discoverable by anyone inspecting the website. Security experts generally consider such exposure a breach, as the data was not adequately protected from unauthorized access. The incident highlights ongoing risks in cloud storage misconfigurations, which remain a leading cause of data leaks across industries.

Tags: Security
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate