Submit incident
Documented

A Deepfake Service Left 100,000 Explicit AI Images in an Unprotected Database

March 31, 2025
Curated by Team Raidu · Reviewed by Shiva Ganesh
aiid:1010View source ↗
LinkedInX

What happened

In March 2025, cybersecurity researcher Jeremiah Fowler found an unprotected database containing 47.8 gigabytes of files linked to a South Korean AI platform called GenNomis, operated by a company called AI-NOMIS. The database was fully open, requiring no authentication to access. Inside it sat nearly 100,000 files, most of them AI-generated images produced by a service that advertised face-swapping and explicit content generation to the public.

GenNomis sold access to tools that let users swap faces onto other bodies and generate nudified images from uploaded photos. That combination, face recognition feeding into explicit output generation, is precisely the kind of service that researchers and regulators had been flagging as a structural harm waiting to materialize. The platform was live, had users, and was storing everything those users created, all in a database with no password protecting it.

The content Fowler found included explicit deepfake images depicting celebrities. The exposure raised immediate questions about how these images were generated in the first place, because services of this type are built on inputs provided by users, and those inputs are not screened for consent. A person's face can be fed into the pipeline without their knowledge, and the output is stored alongside everything else the platform has ever produced. That output sat, unencrypted and publicly accessible, for an undetermined period before the researcher's report triggered a takedown.

The security failure and the consent failure are distinct problems that arrived together. Leaving a 47.8-gigabyte dataset exposed is a data hygiene error, the kind that gets patched quickly once someone finds it. The absence of any content safeguard within the platform itself is a different kind of problem entirely. Nothing in the platform's design prevented the generation of images that the depicted individuals never agreed to. The database was the symptom; the pipeline was the underlying failure.

What neither the researcher's report nor the incident record contains is any verifiable log of what was generated, when, by whom, or on whose likeness. Platforms operating in this space produce output continuously and store it without a layer that could answer basic accountability questions after the fact. A provable record of what a system did, what inputs it accepted, and what it produced, would not undo the breach, but it would make it possible to trace responsibility clearly and quickly, rather than leaving those questions unanswerable once a database is quietly taken offline.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

AI Incident Database
Also catalogued in
A Deepfake Service Left 100,000 Explicit AI Images in an Unprotected Database
2025-03-31