A Deepfake Service Left 100,000 Explicit AI Images in an Unprotected Database
What happened
In March 2025, cybersecurity researcher Jeremiah Fowler found an unprotected database containing 47.8 gigabytes of files linked to a South Korean AI platform called GenNomis, operated by a company called AI-NOMIS. The database was fully open, requiring no authentication to access. Inside it sat nearly 100,000 files, most of them AI-generated images produced by a service that advertised face-swapping and explicit content generation to the public.
GenNomis sold access to tools that let users swap faces onto other bodies and generate nudified images from uploaded photos. That combination, face recognition feeding into explicit output generation, is precisely the kind of service that researchers and regulators had been flagging as a structural harm waiting to materialize. The platform was live, had users, and was storing everything those users created, all in a database with no password protecting it.
The content Fowler found included explicit deepfake images depicting celebrities. The exposure raised immediate questions about how these images were generated in the first place, because services of this type are built on inputs provided by users, and those inputs are not screened for consent. A person's face can be fed into the pipeline without their knowledge, and the output is stored alongside everything else the platform has ever produced. That output sat, unencrypted and publicly accessible, for an undetermined period before the researcher's report triggered a takedown.
The security failure and the consent failure are distinct problems that arrived together. Leaving a 47.8-gigabyte dataset exposed is a data hygiene error, the kind that gets patched quickly once someone finds it. The absence of any content safeguard within the platform itself is a different kind of problem entirely. Nothing in the platform's design prevented the generation of images that the depicted individuals never agreed to. The database was the symptom; the pipeline was the underlying failure.
What neither the researcher's report nor the incident record contains is any verifiable log of what was generated, when, by whom, or on whose likeness. Platforms operating in this space produce output continuously and store it without a layer that could answer basic accountability questions after the fact. A provable record of what a system did, what inputs it accepted, and what it produced, would not undo the breach, but it would make it possible to trace responsibility clearly and quickly, rather than leaving those questions unanswerable once a database is quietly taken offline.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.