9 million photos of people's faces were shared publicly online by hackers


(Dan Tri) - A database containing 9 million images of human faces has been publicly posted online by hackers. This poses the risk of these images being used for malicious purposes, including creating fake content using AI.

9 million face photos globally may have been used by hackers for malicious purposes (Illustration: Wired).
American security researcher Jeremiah Fowler discovered a 450GB database shared publicly on the Internet, allowing anyone to download and use it without going through any authentication steps.
This data contains more than 9 million images of human faces worldwide.
Digging deeper into the shared data, Jeremiah Fowler found that these were leaked images from ClarityCheck. This is an online information lookup service, allowing users to search for data linked to phone numbers, emails or images.
For example, when a user posts a picture of any person, ClarityCheck will search to detect pictures that person has shared on the Internet, personal social networking site or email of the person in the photo...
"Use reverse image search to identify anyone in an image. Find names, social media profiles and online presence in just seconds," ClarityCheck's website introduces its service.
Although ClarityCheck affirms that it does not store faces in images shared by users to search for information. However, leaked data shows that ClarityCheck seems to have stored all facial images shared by users, but has no solution to protect this important data.
Jeremiah Fowler is not sure how long ClarityCheck's data has been exposed, but he is concerned that this data may have been exploited and used by bad guys long before he discovered it and sent a warning to ClarityCheck.
According to Jeremiah Fowler, the most dangerous thing is that people whose faces appear in ClarityCheck's leaked data may not know that their faces may have been used by bad guys.
"Many people use someone else's face to post on ClarityCheck to search for information, so that person themselves is not aware of what purpose their face can be used," commented Jeremiah Fowler.
Security experts say that leaking biometric data such as face, voice or fingerprint will be even more dangerous than revealing account login passwords. The reason for this is because users can change their online account password in case of disclosure, but cannot change their face, voice or fingerprint.
Facial data can be used to train artificial intelligence models to improve facial recognition capabilities, create new portraits of people on demand, or can even be exploited to create fake images and videos using AI, which may include pornographic or criminal content.