Reverse image search platform exposed 9 million images
I recently discovered a publicly exposed database that was neither password-protected nor encrypted. The database contained approximately 9,042,977 image files totaling 450.2GB of data. The exposed records consisted primarily of facial images stored in folders labeled “faces” and “profiles.” In a limited sample of the exposed images I reviewed as part of the investigation, I observed facial images of adults, teens, and children. These included what appeared to be profile images, screenshots, and physical photographs that appeared to have been uploaded for reverse image searches or other identity verification purposes.
Upon further research, I was able to determine that the files belonged to a U.S.-registered company called ClarityCheck. The page source data showed the cloud storage database url where the images are stored. Although the records belonged to ClarityCheck, it is not known whether the database was owned and managed directly by them or by a third-party contractor.
According to their website, ClarityCheck offers “an online digital investigation service that uses reverse image search technology and claims to help users identify individuals, detect catfishing, investigate suspicious online profiles, and perform OSINT-based identity verification”.
I immediately sent a responsible disclosure notice to ClarityCheck alerting them to the exposure of millions of facial images accessible to anyone with an internet connection. The database was restricted from public access and was no longer accessible at the time of publication. I received a reply stating, “Thank you for your diligent and responsible disclosure. I completely understand your concerns regarding the exposure of sensitive images and the associated privacy risks. We greatly appreciate ethical researchers like you who bring these matters to our attention so we can act swiftly to protect our users' data and privacy.”
It is not known how long the database had been publicly accessible before I discovered it, nor whether any unauthorized parties may have accessed the records. Only an internal forensic investigation could determine whether additional access occurred or whether the data was downloaded by third parties.
This collage of screenshots, taken from a limited sample, shows how the images appeared in the exposed database. We’ve applied redactions here to prevent further exposure.
This screenshot shows the total image counts and folders named “faces” and “profiles.”
This image shows a collage of images of children as an example of how their faces were uploaded to the database.
This screenshot shows the public page source identifying the storage database where the images are collected.
The potential risk from a biometric data exposure does not fully depend on whether a person’s name, email address, or other traditional identifiers are stored alongside each image. Facial images are fundamentally different from many other types of personal data because the face itself is the identifying characteristic and is used as a search key. In the case of a service like ClarityCheck, the marketed purpose of the platform is the re-identification of individuals by allowing users (anonymous and registered) to upload an image of a person and attempting to connect that image to publicly available information, online profiles, or other identifying records.
While a facial image alone is generally not enough to steal someone’s identity, the risks increase when it is combined with other personal data that could be used to build a more complete profile of an individual. Hypothetically, publicly available photos of real individuals could be misused to make scams and impersonation attempts appear more credible. For example, criminals or scammers could identify the individual, create fake social media profiles using an exposed image, pretend to be that person contacting friends or family, or include the photo in phishing messages to gain someone's trust and extract additional personal or financial information. Or they could simply use the image as a generic persona without knowing the person’s identity.
ClarityCheck’s website includes a disclaimer stating that it does not offer facial recognition or identity verification and instructing users to upload only images they have the right to share. Despite this consent requirement, the service description page claims their “reverse image search can be used to identify anyone in a photo, find names, social profiles, and online presence in seconds.”
Under ClarityCheck’s terms and conditions, Section 14 (User Consent for Reverse Image Lookup) states, “By utilizing the reverse image lookup feature, you affirm that you have the legal right to upload any image associated with your search. You further consent to the temporary storage and processing of the image as outlined in our data retention policy, which states that uploaded images will be stored for fourteen (14) days before being automatically deleted.” However, I observed images in the publicly accessible database with timestamps that exceeded this 14-day retention period. This also raises the question of oversight and compliance regarding images users submit and whether they have verified consent.
Many of the uploaded images I saw may have originated from third-party sources such as private profiles, social media accounts, dating app accounts, screenshots, or physical photographs uploaded by third-party users. It is hypothetically possible that, in some cases, the individuals depicted were unaware that their facial images were being collected, indexed, or stored without them ever interacting with the ClarityCheck platform or service directly.
While the service claims to identify individuals from a photo,images uploaded to the service could potentially be used for unintended purposes if they are exposed in a data breach. Once data is exposed in a breach, there is a possibility it could also be accessed and used by data brokers, criminals, or even nation-states without the knowledge of the individual or the organization responsible for collecting and storing the data. I am not claiming that in this case the data was at risk or accessed by third -parties; I am only highlighting the potential misuse of exposed data.
Serious privacy concerns
Digital privacy is a growing trend, and not everyone wants their facial images publicly available online. Most parents choose to restrict sharing images of children to close family and friends. Research shows young people are far more aware of the potential long-term digital risks associated with AI analysis, facial recognition, deepfakes, and identity misuse.
Many social media users now actively moderate their audiences and contacts, limit public posting, use private accounts, and think more carefully about uploading personal images online. Publicly accessible imagesare a growing privacy risk now that powerful AI tools are widely accessible.
In May 2026, the Guardian reported that multiple UK schools have been blackmailed with AI-generated child abuse images (CSAM) created from photos shared on school websites and social media accounts. I am not implying or claiming that ClarityCheck users or the images they upload are used for this type of material or were ever at risk; I am only highlighting real-world scenarios in the age of easy public access to AI tools that can generate or manipulate biometric facial images for malicious purposes.
Another concern is the rise in facial recognition technology, identity authentication systems, biometric verification tools, and how AI can introduce unforeseen risks. Facial data differs from traditional personally identifiable information (PII) because it is biometric and generally remains persistent. Once biometric facial data is exposed, individuals cannot simply reset or replace their faces in the same way they would change a password or credit card number. Exposed facial datasets could become valuable targets in ways that we may not fully understand today and could pose a range of identity threats in the future as technology becomes more advanced.
It is estimated that AI computational training power has doubled nearly every 6 to 12 months since 2010. AI models are already capable of matching unlabeled facial images at scale, even without associated names or profile information. There is a very realistic fear that large image datasets could potentially be used for developing or refining facial recognition, tracking, or other surveillance technologies.
If you believe your facial images are being used without your permission, report the incident to the organization responsible for collecting or storing the images, any relevant online platform where the images appear, and your local privacy or data protection authority if applicable. You should also inform family, friends, and business associates so they can be alert to potential impersonation attempts, suspicious messages, or scams that could misuse your image or identity.
I would strongly advise companies that collect and store facial biometric data to treat those images as sensitive information and protect them with the same level of care as other forms of PII. Organizations should encrypt biometric data and limit internal access using role-based permissions and multi-factor authentication (MFA). Organizations should take steps to ensure images are not publicly accessible and regularly conduct independent security assessments and penetration testing to identify vulnerabilities.
As a general rule, companies should minimize the amount of biometric data they retain, securely delete records that are no longer needed, and avoid storing raw facial images whenever possible. This includes educating internal employees or contractors on how to avoid social engineering attempts, phishing attacks, and potential insider threats that could lead to unauthorized access or misuse of biometric information. Organizations should also notify potentially affected individuals if a breach occurs.
As an ethical security researcher, I do not download the data I discover. I only review a limited number of records necessary to verify the exposure and responsibly notify the relevant parties. I do not conduct any activities beyond identifying the vulnerability and documenting the findings.
I imply no wrongdoing by ClarityCheck, Clarity Check Ltd., or any related entities. I do not claim that user data was actively exploited or that any internal systems were compromised. The hypothetical risk scenarios presented in this report are provided strictly for educational and awareness purposes and should not be interpreted as evidence of malicious activity. I publish my findings to raise awareness about data privacy and security issues and to encourage organizations to proactively safeguard sensitive information, biometric data, or other PII.