Full Report
The people-search tool ClarityCheck says its reverse image search service is “private and secure”—but it left a database containing more than 9 million image files exposed.
Analysis Summary
# Morning News Roll-up August 19, 2026
## Overview
Today's intelligence highlights significant data exposures involving biometric search tools and AI platforms, alongside a major counter-intelligence operation against North Korean state-sponsored actors. The most critical incident involves the exposure of 9 million facial images and PII by the people-search tool ClarityCheck.
## Top Stories
### ClarityCheck Database Misconfiguration Exposes 9 Million Images
- Summary: The reverse image search service ClarityCheck left a 450 GB Amazon S3 bucket publicly accessible. The exposure included over 9 million image files used for facial recognition, including photos of children, as well as a second misconfiguration that leaked user email addresses and phone numbers. The data was accessible via a URL embedded in the site's public code.
- Source: hxxps://www[.]wired[.]com/story/reverse-lookup-service-exposed-millions-of-photos-of-peoples-faces/
### Private Claude AI Chats Indexed in Search Results
- Summary: Private conversations between users and Anthropic’s Claude AI chatbot were found indexed in Google and Bing search results. The incident highlights failures in web crawler exclusions (robots.txt) or session management, leading to the public exposure of ostensibly private AI interactions.
- Source: hxxps://www[.]wired[.]com/story/private-claude-chats-exposed-in-google-and-bing-search-results/
### Researcher Infiltrates North Korean Hacking Infrastructure
- Summary: Security researcher Vangelis Stykas maintained access to North Korean state-sponsored servers for nearly two years. The findings reveal that the threat actors successfully breached hundreds of networks globally, providing a rare look into their command-and-control (C2) operations and post-exploitation activities.
- Source: hxxps://www[.]wired[.]com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide/
***
# ClarityCheck Data Exposure
ClarityCheck, a "people-finder" tool offering reverse image and PII searches, suffered a massive data leak due to unsecured cloud storage, contradicting its "private and secure" marketing claims.
## Key Points
- **Massive Biometric Exposure:** Approximately 9 million image files totaling 450 GB were stored in an unencrypted, password-less state.
- **Sensitive Categories:** Exposed data included folders specifically labeled "faces" and "profiles," containing images of adults, teenagers, and children.
- **PII Leak:** A secondary misconfiguration exposed the phone numbers and email addresses of individuals being searched or using the platform.
- **Discovery:** The vulnerability was identified by security researcher Jeremiah Fowler, who noted the storage bucket was reachable via a URL found in the company's own source code.
## Threat Actors
- **Attribution:** No malicious actor initiated this breach; it was a result of **internal misconfiguration** by ClarityCheck.
- **Risk:** The exposure makes this data "low-hanging fruit" for identity thieves, stalkers, and state-sponsored actors looking to build facial recognition databases.
## TTPs
- **Cloud Misconfiguration:** Failure to implement Access Control Lists (ACLs) on an Amazon S3 bucket.
- **Insecure Direct Object Reference (IDOR) / Information Leakage:** Publicly exposing the backend storage URL within the client-side website code.
- **Data Scraping:** Use of automated tools to aggregate public records, social media, and other databases into a centralized, searchable repository.
## Affected Systems
- **Storage Infrastructure:** Amazon S3 (Simple Storage Service) buckets.
- **Victim Scope:** Over 9 million image files and an undisclosed number of email addresses and phone numbers.
- **Demographics:** Individuals globally whose images were indexed by the tool, including minors.
## Mitigations
- **Cloud Security Audits:** Implement automated tools to scan for publicly accessible S3 buckets and apply the "Block Public Access" setting at the account level.
- **Data Encryption:** Ensure all sensitive biometric and PII data is encrypted at rest and in transit.
- **Code Scrubbing:** Remove hardcoded backend infrastructure URLs or sensitive metadata from public-facing website source code.
- **Principle of Least Privilege:** Restrict access to facial recognition databases to only authenticated and authorized service accounts.
## Conclusion
The ClarityCheck incident underscores the high risk associated with "people-search" aggregators that collect biometric data without robust security frameworks. For organizations, this highlights the necessity of continuous cloud posture monitoring. For individuals, it serves as a reminder that images uploaded to social media or public profiles are frequently scraped and may be exposed through third-party vulnerabilities regardless of the original platform's privacy settings.