Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology6 min read

Over 9 million facial recognition images leaked in major breach at reverse image search and identity verification service | TechRadar

Another day, another misconfigured database Discover insights about over 9 million facial recognition images leaked in major breach at reverse image search and

TechnologyInnovationBest PracticesGuideTutorial
Over 9 million facial recognition images leaked in major breach at reverse image search and identity verification service | TechRadar
Listen to Article
0:00
0:00
0:00

Over 9 million facial recognition images leaked in major breach at reverse image search and identity verification service | Tech Radar

Overview

News, deals, reviews, guides and more on the newest computing gadgets

Start exploring exclusive deals, expert advice and more

Details

Unlock and manage exclusive Techradar member rewards.

Unlock instant access to exclusive member features.

Get full access to premium articles, exclusive features and a growing list of member rewards.

Over 9 million facial recognition images leaked in major breach at reverse image search and identity verification service

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Researcher inds Clarity Check’s exposed 450GB database with 9M+ user images

Leak included faces, profiles, and photos, risking identity theft and phishing abuse

Company secured access quickly; no evidence of dark web distribution or misuse so far

An online reverse-lookup platform has inadvertently leaked millions of faces on the internet, putting people at risk of identity theft, phishing, and more, experts have warned.

Jeremiah Fowler, a cybersecurity researcher known for hunting exposed databases, recently found one totaling 450.2GB in size.

It contained exactly 9,042,977 image files - profile pictures, screenshots, and scans of physical photographs - all seemingly uploaded by the users. The images showed adults, teenagers, and even children, and were stored in folders labeled “faces” and “profiles”.

Further investigation showed the database belonging to a company called Clarity Check. This is a US-registered firm describing itself as a “reverse phone, email, image, vehicle lookup”, allowing users to identify unknown callers, verify online contacts, check photos, and decode vehicles using publicly available data from “trusted sources”.

It is a legitimate business whose use case grows more important by the day - cybercriminals create fake internet personas every day, and use them in all sorts of schemes, from romance scams, to fake job offers, to anything in between. To do that, they will either steal other people’s photos, obtain (or buy) them on the dark web, or generate them using artificial intelligence.

European cloud giant Nextcloud exposes staff and clients in major data breach

Rental giant Carla leaks user names, emails, and phone numbers ahead of summer holiday break

The biggest data leaker is probably not who you think it is

Being able to verify someone’s identity has become everyone’s essential due diligence, regardless of if it’s a personal or business matter.

As soon as Fowler confirmed who owned the database, he reached out to Clarity Check and responsibly disclosed his findings. The company responded quickly, barring further access, and thanking the researcher for his work.

“I completely understand your concerns regarding the exposure of sensitive images and the associated privacy risks. We greatly appreciate ethical researchers like you who bring these matters to our attention so we can act swiftly to protect our users' data and privacy,” the company’s representative told Fowler.

Unfortunately, without a deeper investigation on Clarity Check’s end, there is no way of confirming exactly how long the database remained open, or if anyone accessed it before. However, so far there is no evidence of abuse, since a “Clarity Check photo database” is currently not being distributed or sold anywhere on the dark web.

In a world where data theft and leaks are increasingly common, a cause that’s easiest to address, is also the one resulting in most exposures - misconfigured databases. Nowadays, almost every business harvests and stores data about their employees, partners, and customers. Most of them store these files in cloud databases, for easier access and better integration with business intelligence software.

Experts warn "colossal" breach exposes 24 billion records including personal info

Anonymous video chat app leaks data on millions of users — more than 22 million records exposed, including 3 million containing names and email addresses

Hackers claim to be selling 340 million stolen Only Fans records

However, cloud service providers work on a so-called “shared responsibility model”, which means they are responsible for providing industry-standard security features. Users, on the other hand, are responsible for using those features and properly configuring their databases (namely, setting up a strong password or encrypting the content). Unfortunately, many organizations don’t seem to be aware of the shared responsibility model, firmly believing it’s the service provider’s task to keep the data safe. Others simply keep these archives accessible by mistake.

Criminals are aware of this, and are taking advantage of the situation to steal valuable information. By using widely available tools like Shodan, Censys, or FOFA, they can scour the web for unencrypted, non-password protected databases, and exfiltrate data to be used in phishing, business email compromise, and other forms of cyberattacks.

Over the years, Fowler and other searchers have found dozens of enormous databases that have leaked sensitive data on hundreds of millions of people.

In 2026, researchers found that European cloud provider Nextcloud kept an unprotected database on the public internet, containing 367,000 records (8GB) of sensitive employee and client data.

In 2025, IMData Center, a Florida-based data hygiene, enhancement, and append services provider, was leaking 38GB of sensitive personal records. The unencrypted and non-password-protected database held 10,820 in total.

In 2024, sports analytics technology company Track Man exposed sensitive customer data: 110TB and 31,602,260 records. The database had no password.

➡️ Read our full guide to the best antivirus

  1. Best overall: Bitdefender Total Security
  2. Best for families: Norton 360 with Life Lock
  3. Best for mobile: Mc Afee Mobile Security

Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, Io T, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

The price and release date for Xbox's 25th anniversary translucent 'OG green' controller have leaked ahead of Gamescom

Google Messages RCS issues reported by some users — but there's an easy fix

Furious star Steve Way talks hit Hulu and Disney+ show and AI for disabled actors

Chat GPT has started dropping more unexpected f-bombs recently

NATO wants thousands of AI drones guarding its borders — but there’s one thing they won’t be allowed to do

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • News, deals, reviews, guides and more on the newest computing gadgets
  • Start exploring exclusive deals, expert advice and more
  • Unlock and manage exclusive Techradar member rewards
  • Unlock instant access to exclusive member features
  • Get full access to premium articles, exclusive features and a growing list of member rewards

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.