Data Breach Exposes Millions of Personal Photos and Contact Information
A security researcher discovered that the people-search tool ClarityCheck left a database containing over 9 million image files, including photos of people’s faces, publicly exposed. The misconfigured Amazon S3 bucket stored images in unsecured folders named ‘faces’ and ‘profiles,’ accessible via a URL in the company’s website code. The exposed data also included email addresses and phone numbers, posing significant privacy risks. While ClarityCheck secured the database after being contacted by WIRED, the breach highlights vulnerabilities in data management practices. The incident underscores the dangers of accidental data exposure, particularly for sensitive biometric data like facial images. Researchers warn that such exposures could enable identity theft and other malicious activities. The company’s response, though prompt, raises questions about proactive security measures. This incident falls under broader concerns about data privacy and cybersecurity in tech services.
