People finder service leaks 9M faces: How can you be sure you aren’t included?
Many users may be unaware their faces are included.

Jeremiah Fowler/Cybernews
- A "privacy" tool backfires: ClarityCheck left 9 million facial images, including of children, unprotected online.
- You may already be indexed: Since it matches uploads against the web, anyone searched by another user could be caught in the database unknowingly.
- Faces can't be reset: Unlike a password, leaked biometric data is permanent – raising AI surveillance fears.
- The company disputes the leak was "public," citing an unindexed URL – though no login was required to access it.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A reverse-lookup service exposed a 450GB database with over 9 million facial images, raising alarms about AI-powered surveillance.
A reverse lookup platform ClarityCheck that is used to identify unknown callers, verify contacts, and basically research anyone online, has exposed a massive dataset.
According to independent cybersecurity researcher Jeremiah Fowler, who discovered the leak, a 450GB-strong dataset was neither password-protected nor encrypted.
The unprotected dataset contained 9 million images, including some of teenagers and children. Images appear to have originated from third-party sources such as social media and dating sites. Fowler’s report, shared with the Express VPN blog site, alleges that some people don’t know that their images were collected, stored, and now exposed by ClarityCheck.
ClarityCheck has disputed the claims.
Images kept for beyond promised 14 days
Fowler also raised concerns about how long uploaded images were retained. ClarityCheck told users that uploaded images would be “stored for 14 days before being automatically deleted.”
But Fowler said he saw images carrying timestamps beyond that time period.
“This also raises the question of oversight and compliance regarding images users submit and whether they have verified consent,” Fowler said.
It is unknown how long the database was publicly accessible. Fowler also cautioned that while the records belonged to ClarityCheck, it was unclear whether the storage itself was managed by the company or a third-party contractor.
AI surveillance fears
Fowler pointed out that the consequences of having your face stolen could extend far beyond initial exposure.
Large collections of facial images floating on the internet are prime targets for LLM training that could be used to improve facial recognition, tracking, and surveillance systems. Controversial facial recognition systems such as Dubai-based PimEyes have been accused of extracting billions of biometric data points from online images, as revealed in a recent privacy lawsuit.
“AI models are already capable of matching unlabeled facial images at scale, even without associated names or profile information,” Fowler said.
There is a very realistic fear that large image datasets could potentially be used for developing or refining facial recognition, tracking, or other surveillance technologiesindependent cybersecurity researcher Jeremiah Fowler warns.
According to the researcher, the images could also make impersonation and scams more convincing, while photographs of children carry an additional risk of being manipulated into AI-generated child sexual abuse material.
As Fowler says, “Once biometric facial data is exposed, individuals cannot simply reset or replace their faces in the same way they would change a password or credit card number.
“Exposed facial datasets could become valuable targets in ways that we may not fully understand today.”
Are you indexed?
Trying to verify whether your own face has been caught up in Clarity breach is not as straightforward as checking for other forms of data leaks. There's no data leak checker specifically for faces.
Data leak checker services – including our own – can match emails or passwords against known breach datasets – but they can't search or index images.
Check if your data has been leaked
Reverse image searching yourself on ClarityCheck specifically won't answer the question either – because the exposed server wasn't indexed – and it would hand them a fresh photo of your face.
According to CyberNews research team, the only route to a definitive answer is to invoke your GDPR rights if you're in the UK or EU.
ClarityCheck's privacy policy lists a privacy officer contact. Put these questions to them directly:
- Do you hold, or have you held, any image of me in the faces or profiles stores?
- Was any image of me within the set exposed between [DATE1] and [DATE2]?
- What was the source of each image, and which user account submitted it?
- Was an Article 34 notification to affected individuals considered, and on what basis was it decided against?
It's also worth raising ClarityCheck's own stated retention policy – their privacy policy claims uploaded images are held for no longer than 14 days. With 9 million files in the bucket, that claim is difficult to reconcile.
ClarityCheck disputes claims
When approached by Wired, ClarityCheck disputed that the data was actually "publicly exposed," arguing that accessing it required an unindexed URL – implying obscurity was a form of protection.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
However, this claim was contested: the images required no authentication at all, and Fowler was able to find the URLs simply by examining its own code.