An internet site known as UK Visa Portal is publicly exposing the passports and selfie pictures of candidates who signed up and paid the location to acquire a U.Ok immigration visa, TechCrunch has discovered.
An nameless individual notified TechCrunch concerning the safety lapse, saying that the web site is exposing not less than 100,000 paperwork from individuals who uploaded their passports and selfies to the web site as a part of the appliance course of.
The web site shouldn’t be affiliated with the U.Ok. authorities, and some have complained that they mistakenly paid a price to this firm as an alternative of utilizing the official GOV.UK web site.
TechCrunch confirmed that UK Visa Portal is the supply of the info leak and verified the authenticity of the uncovered knowledge by contacting affected people to ask if their info was correct.
UK Visa Portal doesn’t have a strategy to report safety points by way of its web site, nor does its web site present names or contact info for the corporate’s administration. TechCrunch despatched an e mail to the deal with listed on UK Visa Portal’s web site to alert the corporate that it has an ongoing safety lapse and to ask who in administration can settle for particular particulars to resolve the difficulty. Given the sensitivity of the uncovered knowledge, TechCrunch defined that it couldn’t share specifics with the corporate’s normal buyer help inbox as a result of it couldn’t assure that the uncovered knowledge wouldn’t be misused.
As a substitute, TechCrunch heard again from the corporate’s purported attorneys and public relations agency. TechCrunch defined once more that given the character of the uncovered recordsdata, it may solely share particulars immediately with the corporate’s administration, and requested that they put TechCrunch in contact with them.
TechCrunch has not heard again from UK Visa Portal’s administration. The safety lapse has nonetheless not been mounted.
Whereas the safety problem is ongoing, TechCrunch believes it’s within the public curiosity that individuals who use the corporate’s providers are conscious of the difficulty. TechCrunch shouldn’t be publishing exact particulars in an effort to reduce any additional danger to their info.
It’s not essential to make use of a third-party service to use for a U.Ok. digital journey authorization, until you’re retaining an immigration legal professional, and candidates ought to apply by way of the U.Ok. authorities’s web site.
While you buy by way of hyperlinks in our articles, we might earn a small fee. This doesn’t have an effect on our editorial independence.