Unsecured 450 GB ClarityCheck Database Exposes Facial Biometrics and Private Personal Records Online A massive 450 GB cloud database containing face scans, screenshots, and personal records from people finder tool ClarityCheck was left unprotected online, posing major biometric privacy risks. A critical privacy vulnerability has emerged surrounding personal identification platforms after an online search directory left a massive database of sensitive images unprotected on the public internet. Security analysis revealed that the database belonging to people-finder service ClarityCheck was hosted on an unsecured Amazon S3 bucket without password protection or basic authentication. Independent security researcher Jeremiah Fowler discovered the unprotected cloud repository, which contained approximately 450 GB of data. The exposed files included profile pictures, screenshots, and photographs of adults, teenagers, and young children, neatly organized under folders named "faces" and "profiles" that were accessible to anyone via a direct URL embedded in the platform's public source code. How People-Search Platforms Collect and Process Biometric Features ClarityCheck operates within the growing market of web-based background and identity look-up tools. These platforms claim to search across public records, online databases, and general web servers to verify individual identities. ClarityCheck advertises capabilities to perform queries based on phone numbers, physical addresses, vehicle identification numbers (VINs), and full names. In addition, its specialized photo-lookup feature advertises the ability to identify unknown individuals in photographs and surface corresponding social media accounts within seconds. During functionality assessments of the facial recognition feature, the website indicates that it scans facial landmarks and maps unique facial geometry. It then cross-references those geometric features with images found across the web. For a fee, the platform generates comprehensive dossier reports that can detail a person's full name, known addresses, historical location data, public appearances, photos, videos, linked social media profiles, and hidden dating app accounts. Unprotected Exposure Timeline and Unconsented Data Processing According to research findings, the sensitive image repository remained exposed on the open web for several months before access was restricted in July following notification. The delayed response highlights persistent challenges in reporting security vulnerabilities to digital service providers. While accidental data exposures present immediate threats to static information like passwords or contact numbers, exposed biometric data carries permanent consequences because a person's facial geometry cannot be altered or reset. Although ClarityCheck requires users to confirm that they possess legal authorization before uploading photos to its engine, practical usage patterns mean that most victims whose faces were exposed had no knowledge that their biometrics were harvested. Because the service is built specifically for third-party identification, individuals rarely search for themselves. Consequently, targets remain unaware when their images are processed, indexed, and ultimately exposed in public repositories. Fowler highlighted that unauthorized exposure creates systemic vulnerabilities. Automated artificial intelligence crawlers can systematically scrape publicly accessible bucket storage, extract facial feature sets, and ingest the images to train machine learning models. The presence of numerous photographs belonging to minors further amplifies the severity of the exposure. Platform Defense and Industry Exposure Standards Responding to inquiries regarding the incident, a spokesperson for ClarityCheck stated that the company appreciated being alerted to the configuration issue and took immediate steps to restrict access once internal teams were notified. However, the company disputed descriptions characterizing the incident as a public data breach, arguing that typical internet users would not have encountered the files through routine browsing. The spokesperson explained that reaching the temporary storage bucket required precise knowledge of a specific, unindexed URL that could not be discovered through standard search engines or normal platform use. Furthermore, ClarityCheck disputed claims regarding the overall volume of distinct individuals impacted, asserting that the repository contained duplicate, cropped, and resized file variants along with non-image data rather than 9 million unique facial profiles. The company added that it has updated its security reporting channels to streamline future vulnerability submissions, maintaining that its profile data was originally compiled from publicly accessible sources and licensed third-party providers. API Flaws Exposed Contact Information via Browser Manipulation The security investigation also uncovered severe application programming interface (API) misconfigurations within ClarityCheck's website infrastructure. By altering standard URL parameters directly inside any basic web browser, unauthorized users could query individual names and retrieve sensitive personal records. The manipulated endpoints returned lists of prospective email addresses, home addresses, and phone numbers associated with the entered name. Following notifications about the endpoint flaw, ClarityCheck secured the affected web parameters. However, security professionals emphasize that basic web misconfigurations of this nature bypass fundamental privacy boundaries, enabling automated scraping of private contact records without requiring specialized hacking tools. Cybercrime Risks and Structural Biometric Vulnerabilities The cybersecurity industry and regulatory authorities classify data as exposed whenever it becomes reachable on the open internet without mandatory access controls or user authentication. Mark Beare, head of consumer products at cybersecurity firm Malwarebytes, noted that exposure occurs the moment sensitive data is left vulnerable to unauthorized access, regardless of whether malicious exploitation has been conclusively documented. Exposed facial profiles present substantial risks in an era dominated by generative AI and synthetic media. Criminal actors can exploit harvested facial datasets to construct synthetic online personas, facilitate catfishing operations, or bypass visual authentication mechanisms. Strategy director for privacy and data governance at the American Civil Liberties Union (ACLU), Rebecca Williams, observed that platforms relying on highly sensitive personal data for identity verification carry structural risks. Because their core business model relies on aggregating sensitive biometric records, security incidents remain an inherent hazard even when robust encryption and minimization controls are implemented. What this means for you • Globally and Across India: Facial biometric data cannot be changed like a password if leaked, creating persistent risks of AI-generated identity theft and catfishing. • Personal Privacy Impact: Unconsented harvesting and public exposure of facial scans on identity tools highlights severe digital privacy risks for ordinary internet users. Questions & Answers 1. What type of data was exposed in the ClarityCheck breach? The exposure contained roughly 450 GB of data, including face scans, profile photos of adults and children, screenshots, email addresses, phone numbers, and physical addresses. 2. How was the database left unsecured? The files were stored in an Amazon S3 storage bucket without password protection or authentication, accessible via direct URLs found in the site's code. 3. Who discovered the security flaw? Independent cybersecurity researcher Jeremiah Fowler discovered the unprotected cloud database. 4. Has ClarityCheck fixed the exposed vulnerabilities? Yes, after being contacted, ClarityCheck restricted access to the cloud storage bucket and secured the misconfigured API endpoints. https://trendkia.com/en/security/claritycheck-ke-anasikyorda-klauda-sarvara-se-450-gb-pheshiyala-deta-lika-niji-janakariyan-jokhima-men-18393 TrendKia — Har trend, sabse pehle.