Did you upload a photo to the internet? 9 million user faces leaked to the web

Have you ever used an online service to check who is behind a Facebook profile or an unknown phone number? Many of us upload photos and personal details to these sites to perform due diligence and protect ourselves from scammers. However, such a service, intended to protect us, has itself become a source of serious danger, as millions of user face photos were completely exposed on the open web.

Source
Did you upload a photo to the internet? 9 million user faces leaked to the web
Photo: Now14 / פייסבוק | צילום: שאטרסטוק

Have you ever used an online service to check who is behind a Facebook profile or an unknown phone number? Many of us upload photos and personal details to these sites to perform due diligence and protect ourselves from scammers. However, such a service, intended to protect us, has itself become a source of serious danger, as millions of user face photos were completely exposed on the open web.

How did millions of face photos leak?

Cybersecurity researcher Jeremiah Fowler recently discovered a breached database with a volume of about 450 gigabytes. The database contained exactly 9,042,977 image files of faces, profile pictures, and scans of physical photographs uploaded by users. The images, which included adults, teenagers, and even children, belonged to the American company ClarityCheck, which offers identity verification services and reverse search for phone numbers, emails, and photos.

The great danger in exposing such a database is misuse by hackers and internet scammers. Real face photos are a valuable asset for cybercriminals, who use them to create fake profiles, commit romance scams, impersonate other people, or engineer targeted phishing attacks. Fortunately, the company blocked access to the database immediately after the report, and as of now, there is no evidence that the information was sold on the dark web.

Why do databases remain exposed?

This leak is the result of a misconfiguration of the cloud database, which remained open without a password or encryption. Many companies tend to forget that cloud data security is their full responsibility, and not just that of the cloud provider. Similar cases have occurred in the past with companies like TrackMan, which exposed tens of millions of records, or the company IMDataCenter, which left tens of gigabytes of sensitive information completely exposed on the web.

Related News