Over 9 million facial recognition images leaked in major breach at reverse image search and identity verification service
Date:
Thu, 20 Aug 2026 11:05:00 +0000
Description:
ClarityCheck locks down huge database after being notified about the spill.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Researcher inds ClarityChecks exposed 450GB database with 9M+ user images Leak included faces, profiles,
and photos, risking identity theft and phishing abuse Company secured access quickly; no evidence of dark web distribution or misuse so far An online reverse-lookup platform has inadvertently leaked millions of faces on the internet, putting people at risk of identity theft , phishing, and more, experts have warned.
Jeremiah Fowler, a cybersecurity researcher known for hunting exposed databases, recently found one totaling 450.2GB in size. It contained exactly 9,042,977 image files - profile pictures, screenshots, and scans of physical photographs - all seemingly uploaded by the users. The images showed adults, teenagers, and even children, and were stored in folders labeled faces and profiles. Latest Videos From TechRadar Watch full video here: What happened? Further investigation showed the database belonging to a company called ClarityCheck. This is a US-registered firm describing itself as a reverse phone, email, image, vehicle lookup, allowing users to identify unknown callers, verify online contacts, check photos, and decode vehicles using publicly available data from trusted sources.
It is a legitimate business whose use case grows more important by the day - cybercriminals create fake internet personas every day, and use them in all sorts of schemes, from romance scams, to fake job offers, to anything in between. To do that, they will either steal other peoples photos, obtain (or buy) them on the dark web, or generate them using artificial intelligence.
You may like European cloud giant Nextcloud exposes staff and clients in
major data breach Rental giant Carla leaks user names, emails, and phone numbers ahead of summer holiday break The biggest data leaker is probably not who you think it is
Being able to verify someones identity has become everyones essential due diligence, regardless of if its a personal or business matter. How ClarityCheck responded As soon as Fowler confirmed who owned the database, he reached out to ClarityCheck and responsibly disclosed his findings. The company responded quickly, barring further access, and thanking the
researcher for his work. Are you a pro? Subscribe to our newsletter Sign up
to the TechRadar Pro newsletter to get all the top news, opinion, features
and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
I completely understand your concerns regarding the exposure of sensitive images and the associated privacy risks. We greatly appreciate ethical researchers like you who bring these matters to our attention so we can act swiftly to protect our users' data and privacy, the companys representative told Fowler.
Unfortunately, without a deeper investigation on ClarityChecks end, there is no way of confirming exactly how long the database remained open, or if
anyone accessed it before. However, so far there is no evidence of abuse, since a ClarityCheck photo database is currently not being distributed or
sold anywhere on the dark web. Exposing people to hackers In a world where data theft and leaks are increasingly common, a cause thats easiest to address, is also the one resulting in most exposures - misconfigured
databases . Nowadays, almost every business harvests and stores data about their employees, partners, and customers. Most of them store these files in cloud databases, for easier access and better integration with business intelligence software. What to read next Experts warn "colossal" breach exposes 24 billion records including personal info Anonymous video chat app leaks data on millions of users more than 22 million records exposed, including 3 million containing names and email addresses Hackers claim to be selling 340 million stolen OnlyFans records
However, cloud service providers work on a so-called shared responsibility model, which means they are responsible for providing industry-standard security features. Users, on the other hand, are responsible for using those features and properly configuring their databases (namely, setting up a
strong password or encrypting the content). Unfortunately, many organizations dont seem to be aware of the shared responsibility model, firmly believing
its the service providers task to keep the data safe. Others simply keep
these archives accessible by mistake.
Criminals are aware of this, and are taking advantage of the situation to steal valuable information. By using widely available tools like Shodan, Censys, or FOFA, they can scour the web for unencrypted, non-password protected databases, and exfiltrate data to be used in phishing, business email compromise, and other forms of cyberattacks.
Over the years, Fowler and other searchers have found dozens of enormous databases that have leaked sensitive data on hundreds of millions of people.
In 2026, researchers found that European cloud provider Nextcloud kept an unprotected database on the public internet, containing 367,000 records (8GB) of sensitive employee and client data.
In 2025, IMDataCenter, a Florida-based data hygiene, enhancement, and append services provider, was leaking 38GB of sensitive personal records. The unencrypted and non-password-protected database held 10,820 in total.
In 2024, sports analytics technology company TrackMan exposed sensitive customer data: 110TB and 31,602,260 records. The database had no password.
The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/over-9-million-facial-recognition-image s-leaked-in-major-breach-at-reverse-image-search-and-identity-verification-ser vice
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)