9,042,977 images totaling 450.2 gigabytes were left accessible in a publicly exposed database without password protection or encryption.
The exposure: scale, contents, and immediate facts
Security researcher Jeremiah Fowler discovered a publicly accessible database containing 9,042,977 image files that together occupied 450.2 gigabytes. The images included facial photographs of adults, teenagers and children in several formats: profile pictures, screenshots and physical photographs. According to the reporting, the files belonged to ClarityCheck, a digital investigation service that uses reverse image search for OSINT-based identity verification.
Discovery and responsible disclosure
Fowler reached out to the organization with a responsible disclosure notice after locating the open repository. The organization responded with gratitude for the notice and restricted the database from public access. Fowler also noted that there is no evidence that any malicious actor accessed or exploited the database, and observers have treated discussions of possible ramifications as hypothetical in the absence of confirmed misuse.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramblePotential risks tied to exposed facial imagery
Even without confirmed access by third parties, the nature and scale of the data raise privacy and security concerns. The exposed repository contained millions of facial images spanning age groups, which—if placed in the wrong hands—could enable impersonation, identity fraud, or the training and refinement of facial-recognition models. The reporting highlights a particularly sensitive vector: the presence of children’s faces. It notes that recent events have shown cybercriminals creating AI-generated child sexual abuse material (CSAM) of students to extort schools, linking the exposure of children’s images to an especially acute privacy and safety risk.
What this means for ClarityCheck's clients, parents, and security teams
- ClarityCheck's clients and procurement leaders: Organizations that rely on OSINT-based identity verification should expect questions about data handling, storage practices and access controls. The presence of an unprotected repository tied to a verification service creates commercial and reputational risk that clients will need addressed by proof of remediation and tightened safeguards.
- Parents and guardians: The inclusion of children’s photographs in the exposed files elevates personal privacy concerns. Even though there is no evidence of misuse, the reported connection between exposed imagery and subsequent criminal misuse in other incidents means caregivers may seek confirmation about how and why images were collected and what steps have been taken to remove or secure those images.
- Security teams and technologists: The incident underscores the operational importance of basic controls—authentication, encryption and access auditing—when storing sensitive biometric imagery. Teams tasked with oversight of third-party services should expect to re-evaluate contractual security requirements and validation procedures for vendors that handle facial data.
Implications and limits of the record
The organization restricted public access after the disclosure, and the reporting makes clear that there is no evidence of data access by malicious actors. That fact shapes how the event should be assessed: the immediate technical harm appears to have been averted, but the hypothetical downstream consequences remain significant if similar lapses go undiscovered. Observers in the report emphasize that while malicious use was not observed in this case, the mere availability of large pools of facial data can enable a range of harmful activities when combined with modern image-generation and impersonation techniques.
The sequence in this case—discovery by an independent researcher, a responsible disclosure, and a rapid restriction of access—illustrates a constructive remediation path. It also highlights the thin margin between discovery by a good-faith researcher and discovery by a malicious actor: unprotected repositories containing biometric data carry an outsized potential for harm should they be found by the wrong party.
Whether through internal controls, contractual requirements for third parties, or industry best practices, the core issue shown here is simple and stubborn: biometric imagery is highly sensitive, and the storage and exposure of millions of faces demands protections that were not present in this instance. The organization involved has taken the first remedial steps; unanswered for now are follow-up actions such as notification to affected individuals and the longer-term governance changes that ClarityCheck’s clients and partners may request.
For the moment, the record ends on two concrete facts: nearly 9.05 million images and 450.2 gigabytes were publicly accessible, and the database has since been restricted after responsible disclosure. The broader question left by those facts is not technical novelty but stewardship—who is responsible for protecting images of people, and how reliably can that responsibility be enforced when a service trades on the collection and processing of facial imagery?
Original reporting: https://www.securitymagazine.com/articles/102505-9m-images-exposed-by-facial-recognition-platform




