ClarityCheck, a reverse image search and people-finder service, left over 9 million image files accessible online in an unsecured Amazon S3 bucket, according to independent security researcher Jeremiah Fowler. A separate misconfiguration exposed users' email addresses and phone numbers. The database contained approximately 450 GB of images—profile photos, screenshots and other photographs of adults, teenagers and children—organized in folders labeled "faces" and "profiles." Anyone with the URL, discoverable in ClarityCheck's publicly available website code, could access the files.

The exposure lasted months. Fowler's initial attempts to contact ClarityCheck went unanswered before the company secured the database in July after WIRED reached out.

ClarityCheck's core business depends on this exact capability. The service markets itself as able to "identify anyone in a photo" and locate social media profiles "in seconds." Users can search by phone number, email, vehicle identification number or name. The people-search category has exploded as a business model—companies monetize identity linkage across datasets that individuals often don't know contain their images.

Herein lies the structural problem: ClarityCheck requires users to attest they have permission to upload photos, but the subjects of those photos almost never grant explicit consent. Fowler noted that "people might not know that their image had been dumped into this database." The service's design for identification means subjects operate without awareness.

"An AI bot could crawl it, extract faces, and use them for training," Fowler said. That observation cuts to why the breach matters beyond privacy—facial datasets have become raw material for AI development. The same vulnerability that exposed 9 million faces creates an incentive structure for bad actors to harvest them.

A ClarityCheck spokesperson said the company "appreciated" Fowler's alert and "acted immediately to restrict access" once the issue reached the appropriate teams. The company disputed characterizing the data as "publicly exposed," arguing that "an ordinary member of the public" would not have encountered it and that the term "implies large-scale public access."

That semantic pushback misses the point. For a people-search business, the liability isn't operational—it's structural. Storing hundreds of gigabytes of biometric data in cloud infrastructure, relying on user attestations as the consent mechanism, and operating in a regulatory gray zone where facial identification rights remain unsettled, creates persistent risk. Other players in the space face the same architecture. Until the business model itself changes—either through regulation mandating explicit subject consent or through liability costs making it uneconomical—similar breaches will recur.