Over 9 million facial recognition images leaked in major breach at reverse image search and identity verification service
A reverse image search and identity verification service suffered a major data breach, exposing more than 9 million facial recognition images. The scale of the leak places biometric data belonging to millions of individuals in the hands of unknown actors.
Why this matters: Facial data is not a password. You cannot reset your face. Once it leaks, it is gone in any meaningful sense. Services that collect biometric images for identity verification are sitting on some of the most sensitive personal data that exists, and this breach shows what happens when that data is held without adequate protection. Nine million faces is not an edge case. It is a mass exposure of people who handed over their biometrics because a service asked them to. The company collected the data. The company bears the responsibility.
Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.