A web site known as UK Visa Portal is publicly exposing the passports and selfie photographs of candidates who signed up and paid the location to acquire a U.Okay immigration visa, TechCrunch has discovered.
An nameless individual notified TechCrunch in regards to the safety lapse, saying that the web site is exposing at the very least 100,000 paperwork from individuals who uploaded their passports and selfies to the web site as a part of the applying course of.
The web site will not be affiliated with the U.Okay. authorities, and some have complained that they mistakenly paid a price to this firm as a substitute of using the official GOV.UK website.
TechCrunch confirmed that UK Visa Portal is the supply of the info leak and verified the authenticity of the uncovered knowledge by contacting affected people to ask if their data was correct.
UK Visa Portal doesn’t have a solution to report safety points by its web site, nor does its web site present names or contact data for the corporate’s administration. TechCrunch despatched an e mail to the tackle listed on UK Visa Portal’s web site to alert the corporate that it has an ongoing safety lapse and to ask who in administration can settle for particular particulars to resolve the difficulty. Given the sensitivity of the uncovered knowledge, TechCrunch defined that it couldn’t share specifics with the corporate’s normal buyer assist inbox as a result of it couldn’t assure that the uncovered knowledge wouldn’t be misused.
As an alternative, TechCrunch heard again from the corporate’s purported attorneys and public relations agency. TechCrunch defined once more that given the character of the uncovered information, it may solely share particulars immediately with the corporate’s administration, and requested that they put TechCrunch in contact with them.
TechCrunch has not heard again from UK Visa Portal’s administration. The safety lapse has nonetheless not been fastened.
Whereas the safety difficulty is ongoing, TechCrunch believes it’s within the public curiosity that individuals who use the corporate’s providers are conscious of the difficulty. TechCrunch will not be publishing exact particulars in an effort to reduce any additional danger to their data.
It’s not crucial to make use of a third-party service to use for a U.Okay. digital journey authorization, except you’re retaining an immigration legal professional, and candidates ought to apply through the U.K. government’s website.
While you buy by hyperlinks in our articles, we may earn a small commission. This doesn’t have an effect on our editorial independence.
