{
  "id": 2123347,
  "title": "Over 9 million facial recognition images leaked in major breach at reverse image search and identity verification service",
  "url": "https://urgent.news/2026/08/20/over-9-million-facial-recognition-images-leaked-in-major-breach-at",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-20T11:05:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/over-9-million-facial-recognition-images-leaked-in-major-breach-at-reverse-image-search-and-identity-verification-service"
  },
  "original_language": "en",
  "account": "An online reverse-lookup platform inadvertently leaked millions of faces on the internet, posing risks of identity theft, phishing, and other forms of cyberattacks, according to cybersecurity experts. Jeremiah Fowler, a researcher specializing in discovering exposed databases, recently identified a database totaling 450.2GB in size. This database contained 9,042,977 image files, which included profile pictures, screenshots, and scans of physical photographs, all seemingly uploaded by users. The images showed individuals ranging from adults to children, stored in folders labeled \"faces\" and \"profiles.\" The database belonged to a US-based company called ClarityCheck, which provides reverse phone, email, image, vehicle lookup services. ClarityCheck is a legitimate business that assists users in identifying unknown callers, verifying online contacts, checking photos, and decoding vehicles using publicly available data from trusted sources. The company acknowledged the breach promptly, limiting access and expressing appreciation for the researcher's responsible disclosure. However, the exact duration of the database's exposure remains unclear, and there is no evidence of the information being distributed or misused on the dark web as of now. Despite the absence of direct evidence of abuse, the incident highlights the ongoing risks associated with data breaches and misconfigured databases. Organizations often store sensitive data in cloud databases, relying on shared responsibility models where providers offer standard security features, while users must also configure and secure their systems appropriately. Cybercriminals exploit this vulnerability by using tools like Shodan, Censys, or FOFA to search for unencrypted, unprotected databases and exfiltrate valuable information for malicious purposes. This leak serves as a reminder of the importance of proper database configuration and heightened awareness of data security practices in preventing potential cyber threats.",
  "summary": "ClarityCheck locks down huge database after being notified about the spill.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}