over:heard
Unclaimed brand page — independent analysis by over:heard, based solely on public coverage.
ClarityCheck logoCClarityCheckclaritycheck.com

Exposed database leaks nine million people’s facial photos

AssessmentTHREATSeverityHIGHEscalation riskHIGHUrgencyHOURS
Analysis as of 2026-08-22 — a dated snapshot of the coverage verified that day.
Evidence-backed — 52 verified facts from 8 sourcesPWTDTD+2View evidence ›

Executive summary

A cybersecurity researcher discovered an unsecured database containing over 9 million facial images belonging to ClarityCheck users, exposing sensitive biometric data.27133347 The exposure represents a preventable failure of the company's duty to secure user data, contradicting its public promise of private and secure searches.69213451 We recommend immediately moving to full responsibility, abandoning technical disputes, and launching a comprehensive security review.10172745 The investigation must determine why images were retained beyond the stated 14-day retention period and whether any unauthorized access occurred.26383940

Mentions (9)

Show 7 moreShow less
Face-search tool ClarityCheck left 9M photos exposed
thenextweb.com iconThe Next Web via research · 2026-08-20
Facial Recognition Leak: 9 Million Images Exposed
technosports.co.in iconTechnoSports Media Group via research · 2026-08-20

Risks / opportunities

THREATRegulatory investigations and potential fines under CCPA, GDPR, and other data protection frameworks for biometric data exposure.89213451
THREATClass-action litigation from affected users whose images were retained beyond stated policies.26383940
THREATSustained media scrutiny focusing on the gap between security promises and practices, amplified by AI and privacy concerns.27203347
OPPORTUNITYDemonstrating industry-leading transparency and security commitment through a thorough public investigation could differentiate ClarityCheck in a crowded market.62937

Best response strategy

REBUILD The unsecured database and retention policy violations constitute a preventable crisis under SCCT—ClarityCheck failed a duty of care it explicitly promised to users.692126343839 Stakeholders will assign blame for both the exposure and the retention violations; denying either compounds reputational harm.274551 Taking responsibility, explaining remediation, and demonstrating changed practices is the only posture that can restore trust.10171824 The company's initial response disputing technicalities ('unindexed URL') must be abandoned immediately in favor of unequivocal accountability.2745

Who is watching, and what each expects from the response:

customersTheir facial images were exposed without consent, potentially violating privacy expectations and the company's stated 14-day retention policy.5825263839
regulatorPotential violations of data protection laws (e.g., CCPA, GDPR) due to unsecured storage of biometric data and images exceeding stated retention periods.8921343951
mediaReporting on a significant data exposure involving sensitive facial images, questioning the company's security practices and transparency.27203347
investorsReputational damage and potential regulatory fines that could impact the company's valuation and future operations.7131416
publicLoss of trust in digital identity verification services and broader anxiety about facial image security in the age of AI training.5254951
employeesInternal morale and confidence in leadership, plus anxiety about job security and company reputation affecting their professional standing.131416

Suggested response plan

T+0-4h
Phase 1 — Contain & verify
Outcome: All internal communications are coordinated, factual accuracy of the exposure is confirmed, and a holding statement is ready for affected stakeholders.27101724
executive
Convene the crisis team to verify the technical facts of the exposure, freeze all external communications, and draft a holding statement acknowledging the issue and our immediate containment action.101724
  1. Legal counsel reviews the verified facts against regulatory obligations.
  2. Technical team confirms the database is secured and begins forensic analysis.
  3. Comms drafts a holding statement for the website acknowledging the exposure and our immediate action to secure it.
Done when: Crisis team convened, database access confirmed restricted, and holding statement approved and ready for publication.
T+4-12h
Phase 2 — Respond & acknowledge
Outcome: A clear, responsible public statement is published, key regulators are notified, and customers are informed through direct channels.6263839
comms
Publish the full public statement on all primary channels, notify relevant data protection authorities, and prepare customer notification scripts for the support team.1018
  1. Publish the approved statement on the company website, LinkedIn, and Twitter.
  2. Legal files necessary breach notifications with relevant state and federal regulators.
  3. Support team receives a script to acknowledge the issue and direct concerned users to the public statement.
Done when: Public statement live on website and social channels, regulator notifications submitted, and support script deployed.
“We have secured the database that was discovered by cybersecurity researcher Jeremiah Fowler and sincerely thank him for bringing this to our attention.1017182444 The security of our users' data is our highest priority, and we have immediately restricted access to these files.61017 We are conducting a thorough investigation into this exposure, including why some images were retained beyond our stated 14-day retention period.263839 We are reviewing our security practices and will implement additional safeguards to prevent this from happening again.1018 We are committed to transparency and will share our findings and the steps we are taking to strengthen our systems.”
website statementpress releasesocial media
T+1-3 days
Phase 3 — Manage & investigate
Outcome: A comprehensive internal investigation is underway, a timeline for findings is established, and proactive media outreach begins.26383940
operations
Launch a deep-dive technical and compliance investigation, appoint an independent third-party auditor, and brief key media contacts on the scope of our review.1840
  1. Technical team forensically analyzes the exposure duration, access logs, and data retention anomalies.
  2. Legal and compliance teams map the findings against data protection regulations and retention policies.
  3. Comms schedules briefings with select journalists to outline the investigation's scope and commitment to transparency.
Done when: Independent auditor engaged, investigation scope document published internally, and media briefings completed.
T+2-4 weeks
Phase 4 — Recover & rebuild
Outcome: Trust begins to be restored through the publication of investigation findings, implementation of new safeguards, and a clear corrective action plan.62937
executive
Publish the investigation findings and corrective action plan, implement the recommended security enhancements, and launch a campaign highlighting the strengthened safeguards.6
  1. Publish a transparent report on the investigation findings and root causes on the website.
  2. Implement all technical safeguards identified by the audit, including encryption and access controls.
  3. Comms develops customer-facing materials explaining the new safeguards and the company's renewed commitment to security.
Done when: Investigation report publicly published, all high-priority security enhancements implemented, and new security page launched on the website.

Evidence sources (8)

Everything this briefing cites — ANCHOR started the story, CONTEXT backs it without naming the brand.

Are you claritycheck.com?

Your crisis desk is ready — claim it to respond. Claiming is free — your response strategy & plan become collaborative, and you get the option to display your response & status updates on this page.

Claim your brand

Follow this story

One short, factual update when this story develops — nothing else, from over:heard.

Email updates

By subscribing you consent to receive email updates about this story. Double opt-in: nothing is sent until you confirm from your inbox. Unsubscribe anytime — one click in every email.

Push notifications

No email needed — alerts appear on this device.

Not claritycheck.com? See what over:heard would flag for your brand. Start free →
Independent media-monitoring briefing compiled by over:heard radar from public coverage. Assessments are decision support — not statements by, or affiliation with, the brands mentioned. · Built from public sources, cited. Every brand has a free, permanent right of reply — editorial policy · Powered by over:heard by wise:able