Is that my Photo?

31224322883?profile=RESIZE_400xCybersecurity researcher Jeremiah Fowler has identified a significant data exposure involving millions of private facial images.  In a collaborative investigation conducted with ExpressVPN, Fowler discovered a publicly accessible database containing approximately 9,042,977 images.   The collection, totaling 450.2GB of data, was found with no password protection or encryption, leaving it open to any internet user who stumbled upon the repository.[1]

The discovery highlights a worrying security lapse for a platform handling highly sensitive personal information. Because the data was stored unencrypted, the risk of unauthorized access and bulk downloading increased substantially.

Evidence found within the repository suggests the database is linked to ClarityCheck, a reverse image search and identity verification service based in the United States. These services typically allow customers to upload photographs to verify a person's identity or scan the internet for other instances of a specific face.

The incident highlights the growing third-party verification industry and the massive amounts of biometric data these companies collect. When such organizations fail to secure their storage environments, they inadvertently create a central resource for malicious actors seeking to exploit personal identities.

The researcher found that the database was organized into clearly labeled folders, including directories named "faces" and "profiles". The content within these folders was varied and deeply personal, containing images of adults, teenagers, and children.  The exposed files included standard profile pictures and personal photographs, which were likely provided by users during the verification process.  The presence of various screenshots suggests the service may have captured data from multiple sources as part of its search operations. The inclusion of images featuring minors makes the security failure particularly serious, as it involves the data of a vulnerable demographic.

The exposure of facial images carries long-term risks that differ from traditional data breaches involving passwords or credit card numbers. Biometric data is permanent; an individual cannot change their facial features if their image is compromised. Consequently, criminals could use this data for sophisticated identity theft, targeted harassment, or creating fraudulent accounts.  Such a large dataset of verified faces is highly valuable for training unauthorized facial recognition algorithms. Without encryption, there was no barrier to prevent an attacker from repurposing these images for harmful digital activities.

This incident reminds us that the convenience of digital identity verification must be balanced with rigorous security hygiene. Experts recommend that any firm handling biometric data must implement multi-layered defense strategies, including encryption at rest and strict access controls.  For consumers, the breach illustrates the importance of understanding the privacy policies of services that require photo uploads.


This article is shared at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC).  For questions, comments, or assistance, please contact the office directly at 1-844-492-7225 or feedback@redskyalliance.com    

Weekly Cyber Intelligence Briefings:
REDSHORTS - Weekly Cyber Intelligence Briefings
https://attendee.gotowebinar.com/register/7855487668891299929

 

[1] https://www.cybersecurityintelligence.com/blog/millions-of-facial-images-exposed-in-data-breach-9657.html

You need to be a member of Red Sky Alliance to add comments!