An internet site known as UK Visa Portal is publicly exposing the passports and selfie images of candidates who signed up and paid the location to acquire a U.Ok immigration visa, TechCrunch has discovered.
An nameless particular person notified TechCrunch in regards to the safety lapse, saying that the web site is exposing no less than 100,000 paperwork from individuals who uploaded their passports and selfies to the web site as a part of the applying course of.
The web site is just not affiliated with the U.Ok. authorities, and some have complained that they mistakenly paid a price to this firm as an alternative of using the official GOV.UK website.
TechCrunch confirmed that UK Visa Portal is the supply of the information leak and verified the authenticity of the uncovered knowledge by contacting affected people to ask if their info was correct.
UK Visa Portal doesn’t have a approach to report safety points by way of its web site, nor does its web site present names or contact info for the corporate’s administration. TechCrunch despatched an e-mail to the deal with listed on UK Visa Portal’s web site to alert the corporate that it has an ongoing safety lapse and to ask who in administration can settle for particular particulars to resolve the difficulty. Given the sensitivity of the uncovered knowledge, TechCrunch defined that it couldn’t share specifics with the corporate’s normal buyer assist inbox as a result of it couldn’t assure that the uncovered knowledge wouldn’t be misused.
As a substitute, TechCrunch heard again from the corporate’s purported attorneys and public relations agency. TechCrunch defined once more that given the character of the uncovered information, it may solely share particulars straight with the corporate’s administration, and requested that they put TechCrunch in contact with them.
TechCrunch has not heard again from UK Visa Portal’s administration. The safety lapse has nonetheless not been fastened.
Whereas the safety concern is ongoing, TechCrunch believes it’s within the public curiosity that individuals who use the corporate’s providers are conscious of the difficulty. TechCrunch is just not publishing exact particulars in an effort to attenuate any additional threat to their info.
It’s not crucial to make use of a third-party service to use for a U.Ok. digital journey authorization, except you’re retaining an immigration legal professional, and candidates ought to apply through the U.K. government’s website.
While you buy by way of hyperlinks in our articles, we might earn a small fee. This doesn’t have an effect on our editorial independence.
