Thursday, 20 August 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

Over 9 million facial recognition images leaked in major breach at reverse image search and identity verification service

TechRadar ·
Over 9 million facial recognition images leaked in major breach at reverse image search and identity verification service

Researcher inds ClarityCheck’s exposed 450GB database with 9M+ user images Leak included faces, profiles, and photos, risking identity theft and phishing abuse Company secured access quickly; no evidence of dark web distribution or misuse so far An online reverse-lookup platform has inadvertently leaked millions of faces on the internet, putting people at risk of identity theft , phishing, and more, experts have warned.

Jeremiah Fowler, a cybersecurity researcher known for hunting exposed databases, recently found one totaling 450.2GB in size.

It contained exactly 9,042,977 image files - profile pictures, screenshots, and scans of physical photographs - all seemingly uploaded by the users.

The images showed adults, teenagers, and even children, and were stored in folders labeled “faces” and “profiles”.

What happened? Further investigation showed the database belonging to a company called ClarityCheck.

This is a US-registered firm describing itself as a “reverse phone, email, image, vehicle lookup”, allowing users to identify unknown callers, verify online contacts, check photos, and decode vehicles using publicly available data from “trusted sources”.

It is a legitimate business whose use case grows more important by the day - cybercriminals create fake internet personas every day, and use them in all sorts of schemes, from romance scams, to fake job offers, to anything in between.

To do that, they will either steal other people’s photos, obtain (or buy) them on the dark web, or generate them using artificial intelligence.

Being able to verify someone’s identity has become everyone’s essential due diligence, regardless of if it’s a personal or business matter.

How ClarityCheck responded As soon as Fowler confirmed who owned the database, he reached out to ClarityCheck and responsibly disclosed his findings.

The company responded quickly, barring further access, and thanking the researcher for his work.

“I completely understand your concerns regarding the exposure of sensitive images and the associated privacy risks.

We greatly appreciate ethical researchers like you who bring these matters to our attention so we can act swiftly to protect our users' data and privacy,” the company’s representative told Fowler.

Unfortunately, without a deeper investigation on ClarityCheck’s end, there is no way of confirming exactly how long the database remained open, or if anyone accessed it before.

Read the full article on TechRadar ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.

More from TechRadar

See all ›

More in Technology

See all ›