ClarityCheck’s exposed biometric databases present major identity theft, fraud risk Consider where your face might be found. Social media, probably. Maybe internet search. It doesn’t naturally occur to anyone that their face may be stored in a publicly exposed database with no security safeguards to speak of. Unencrypted and freely available, your face could be nicked from that database, paired with fake data and used for identity fraud. Cybersecurity researcher Jeremiah Fowler recently happened upon just such a database. According to what he shared with ExpressVPN, it contained 9,042,977 image files totaling 450.2 GB of data, housing the facial biometrics of adults, teens, and children in folders labeled “faces” and “profiles.” “These included what appeared to be profile images, screenshots, and physical photographs that appeared to have been uploaded for reverse image searches or other identity verification purposes,” Fowler says. “Upon further research, I was able to determine that the files belonged to a U.S.-registered company called ClarityCheck.” Treat biometrics with care they warrant: Fowler ClarityCheck offers reverse phone, email, image and vehicle lookup services. Its website describes “an online digital investigation service that uses reverse image search technology and claims to help users identify individuals, detect catfishing, investigate suspicious online profiles, and perform OSINT-based identity verification.” In the case of a service like ClarityCheck, Fowler says, “the marketed purpose of the platform is the re-identification of individuals by allowing users (anonymous and registered) to upload an image of a person and attempting to connect that image to publicly available information, online profiles, or other identifying records.” For ClarityCheck, a side effect was the mass retention of biometric data that, it turned out, anyone could steal. “I imply no wrongdoing by ClarityCheck, Clarity Check Ltd., or any related entities,” Fowler says. “I do not claim that user data was actively