Thursday, October 8, 2026
English edition

Development

Reverse-lookup service exposed millions of photos of people’s faces

August 20, 2026 Development Source: Ars Technica

Reverse-lookup service exposed millions of photos of people’s faces

Share this article

“If you’re trying to find out who a person is, you might not have authorization or permission, so people might not know that their image had been dumped into this database that was public,” Fowler tells WIRED. “An AI bot could crawl it, extract faces, and use them for training. And there are lots of pictures of kids in there.” In a statement sent to WIRED, a spokesperson said that ClarityCheck appreciated Fowler’s efforts to alert the company about the issues. “Once this was drawn to the attention of the appropriate teams, we acted immediately to restrict access,” the spokesperson said. The company disputed any characterization that the data was “exposed,” saying that an “ordinary member of the public” would not have come across it. “We do not accept that data in the temporary storage location was ‘publicly exposed,’ which implies large-scale public access,” the spokesperson says. “Access required knowledge of a specific, unindexed URL that was not discoverable through ordinary use of the ClarityCheck service or a general web search.” The company added that it has “improved” its security reporting procedures to help other researchers contact the company in the future. In addition to the face data, ClarityCheck had also misconfigured its APIs such that its website URLs could be manipulated to reveal data about people simply by entering names; anyone using any consumer browser could have done this. Entering a name into one of the URLs would return multiple potential email addresses, physical addresses, and phone numbers for people with that name. After WIRED contacted the company, the URLs were secured. The ClarityCheck spokesperson said in the statement that the details displayed were “sourced from publicly available information and licensed third-party data providers.” ClarityCheck’s face-search feature allows people to upload an image and then receive a “report” about where that image may appear online and who may be shown in the photo. When a WIRED reporter tested the system using their own face image, the website said it was “scanning facial landmarks” and “mapping unique face geometry” before matching the image to others online and offering a report that could include a full name, addresses, location history, public appearances, photos, videos, social media profiles, and “hidden dating profiles” for a fee. The resulting report named the reporter, provided a biography, and linked to multiple photos of them online. Misconfigurations and accidental exposures are unfortunately common online, but as digital platforms offer more and more automated capabilities for collecting and analyzing sensitive personal data, the stakes grow ever higher for securing information. “Systems that rely on highly sensitive personal information to verify individuals will continue to carry these risks, even with stronger data minimization and security practices, because the model itself depends on collecting sensitive data,” says Rebecca Williams, director of strategy for privacy and data governance at the American Civil Liberties Union. Fowler emphasizes that exposed data, including photos, are more valuable than ever to scammers or cybercriminals. “Let’s say I was in a criminal outfit and I was catfishing people, and I scroll through all these pictures and I pick out 20 of the most attractive people and then I just use their image and AI and I create a persona,” Fowler says.