Updated 24 August 2026: This article has been updated with additional commentary from ExpressVPN chief research officer Dr Pete Membrey on smart glasses, facial imagery and the implications of increasingly capable image-analysis tools.
Someone else can change your password. Your bank can cancel a compromised credit card. An email address can be abandoned if things get bad enough. But your face is rather harder to replace. Well, unless you are in South Korea, but I digress.
That is what makes the discovery of more than nine million facial images in an unsecured database particularly uncomfortable.
Cybersecurity researcher Jeremiah Fowler discovered a publicly exposed database containing 9,042,977 image files totalling approximately 450.2GB, in research conducted in collaboration with ExpressVPN.
The database was neither password-protected nor encrypted. Fowler determined that the files belonged to US-registered company ClarityCheck, although it is not known whether the database itself was managed directly by ClarityCheck or by a third-party contractor.
This isn’t just another database filled with usernames and forgotten passwords.
It contained faces.
More than nine million images
According to Fowler, many of the files were stored in folders labelled “faces” and “profiles”. In the limited sample he examined, Fowler observed images of adults, teenagers and children, including profile images, screenshots and physical photographs that appeared to have been uploaded for reverse-image searches or other identity verification purposes.
There is an important distinction to note. The discovery represents more than nine million image files, not necessarily nine million individual people. A service processing images can create multiple copies, crops or resized versions of the same photograph, so treating the file count as nine million unique identities would be misleading.
Even with that qualification, 450GB of facial imagery sitting without authentication is a substantial privacy exposure.
The nature of the service makes it more concerning again.
ClarityCheck describes itself as an online digital investigation service using reverse-image search technology. According to its website, the service can help users identify individuals, detect catfishing, investigate suspicious online profiles and perform OSINT-based identity verification.
But that introduces an awkward question about consent.
The person uploading a photograph isn’t necessarily the person standing in it.
Who gave permission for your face?
When we hand over a password, fingerprint or face scan to a service ourselves, there is at least a direct relationship between the person providing the information and the organisation receiving it.
Reverse-image searching can break that relationship.
Someone else may possess a photograph of you and upload it to a service to find out who you are. The subject of the photograph may never know the search occurred, let alone know what subsequently happened to the uploaded image.
Fowler observed that many of the images he sampled may have originated from sources including social media, dating apps, private profiles, screenshots and physical photographs uploaded by third parties. He says it is hypothetically possible that some of the people depicted had no idea their images were being collected, indexed or stored.
That makes the presence of photographs of children particularly concerning.
There is another wrinkle.
ClarityCheck’s terms state that images uploaded for reverse-image lookup are temporarily stored and automatically deleted after 14 days. Fowler says he observed images in the exposed database with timestamps exceeding that retention period.
It is also why this story is about more than whether some cloud storage was configured correctly.
We are increasingly using people’s faces as searchable information.
A photograph isn’t necessarily biometric data
There is another distinction worth pointing out.
A photograph containing someone’s face is not automatically the same thing as a stored biometric template.
Facial-recognition systems can analyse characteristics and geometry from an image to identify or compare people, but Fowler’s discovery should not automatically be described as nine million leaked biometric identities unless there is evidence that biometric templates or facial embeddings themselves were exposed.
What we do know is that millions of facial images were accessible, and that those images were associated with a service designed to search using faces.
That is concerning enough without exaggerating it.
Accessible doesn’t mean exploited
There is also no evidence presented that the exposed images were stolen or accessed by an unauthorised third party.
An exposed database is not necessarily the same thing as a confirmed data breach where information is known to have been downloaded or exfiltrated.
According to Fowler, ClarityCheck’s publicly accessible page source revealed the cloud storage database URL where the images were stored. The database itself did not require a password and was not encrypted.
That created the opportunity for unauthorised access, but opportunity and evidence of exploitation are two different things.
Fowler says it is not known how long the database had been publicly accessible or whether anyone else accessed the records. He also explicitly makes no claim that the data was accessed by third parties, noting that only an internal forensic investigation could determine whether additional access or downloads occurred.
It’s an important distinction in security reporting, particularly when the information involved is as sensitive as someone’s face.
You can’t reset your face
The incident nevertheless highlights a growing problem as facial recognition and reverse-image searching become increasingly accessible.
A compromised password can be changed.
A stolen credit-card number can be cancelled.
Even an exposed email address can ultimately be replaced.
The physical characteristics we increasingly use to identify ourselves are different.
Facial photographs can potentially be copied indefinitely, combined with information from other sources, analysed using increasingly capable facial-recognition systems and used in ways the person pictured never anticipated.
Possible risks range from identifying someone who intended to remain anonymous through to stalking, impersonation and other forms of identity abuse.
That doesn’t mean Fowler’s discovery resulted in any of those things.
It means the consequences of poor security around this kind of data can extend well beyond resetting a password.
The camera is only the beginning
There is another side to this problem: collecting the image in the first place is becoming increasingly easy.
In comments provided to Digital Reviews Network following publication of Fowler’s findings, ExpressVPN chief research officer Dr Pete Membrey pointed to the growing availability of camera-equipped smart glasses as an example of how the privacy equation is changing.
The camera itself isn’t particularly new. Smartphones have put cameras in almost everyone’s pocket for years, and discreet wearable cameras existed long before the current generation of smart glasses.
What is changing is what can potentially happen after the photograph is taken.
“The risk doesn’t necessarily end when the recording stops. Once an image exists, other tools can potentially analyse it, identify people, work out where they are or connect it with information about them,” Membrey said.
That distinction matters in the context of the ClarityCheck exposure.
A photograph of an unknown person was once largely just that: a photograph of someone you didn’t know. Today, reverse-image search, facial matching, image recognition and other analysis tools can potentially turn that photograph into the beginning of an investigation.
Who is this person? Where else does their face appear? Where might the photograph have been taken? What other information can be connected to them?
ClarityCheck itself demonstrates part of that changing equation. Its service is designed around using an image to search for information about the person depicted. Fowler’s discovery then raises the separate question of what can happen to those images after somebody else uploads them.
Smart glasses add another dimension because the subject may have no relationship with the device or service involved at all.
As Membrey puts it, “if you’re the one being filmed, you didn’t buy the device, set it up or agree to any of it.”
That is perhaps the more interesting privacy problem posed by increasingly unobtrusive wearable cameras.
The camera isn’t new. What can now be done with the image is.
Following Fowler’s responsible disclosure, the database was restricted from public access and was no longer accessible at the time his findings were published. Fowler also received a response thanking him for bringing the exposure and associated privacy risks to ClarityCheck’s attention.
The immediate exposure may therefore be closed, but the broader question isn’t.
As facial search becomes easier and more powerful, we need to think about more than whether the person conducting a search consented to a company’s terms.
We also need to consider the person on the other side of the camera.
Because your face may increasingly function like an identifier online.
Unlike a password, you only get one.
