A web site referred to as UK Visa Portal is publicly exposing the passports and selfie pictures of candidates who signed up and paid the positioning to acquire a U.Ok immigration visa, information.killnetswitch has discovered.
An nameless individual notified information.killnetswitch concerning the security lapse, saying that the web site is exposing not less than 100,000 paperwork from individuals who uploaded their passports and selfies to the web site as a part of the applying course of.
The web site shouldn’t be affiliated with the U.Ok. authorities, and a few have complained that they mistakenly paid a charge to this firm as an alternative of utilizing the official GOV.UK web site.
information.killnetswitch confirmed that UK Visa Portal is the supply of the information leak and verified the authenticity of the uncovered information by contacting affected people to ask if their data was correct.
UK Visa Portal doesn’t have a solution to report security points by means of its web site, nor does its web site present names or contact data for the corporate’s administration. information.killnetswitch despatched an e mail to the handle listed on UK Visa Portal’s web site to alert the corporate that it has an ongoing security lapse and to ask who in administration can settle for particular particulars to resolve the difficulty. Given the sensitivity of the uncovered information, information.killnetswitch defined that it couldn’t share specifics with the corporate’s basic buyer help inbox as a result of it couldn’t assure that the uncovered information wouldn’t be misused.
As an alternative, information.killnetswitch heard again from the corporate’s purported attorneys and public relations agency. information.killnetswitch defined once more that given the character of the uncovered recordsdata, it might solely share particulars immediately with the corporate’s administration, and requested that they put information.killnetswitch in contact with them.
information.killnetswitch has not heard again from UK Visa Portal’s administration. The security lapse has nonetheless not been fastened.
Whereas the security subject is ongoing, information.killnetswitch believes it’s within the public curiosity that individuals who use the corporate’s providers are conscious of the difficulty. information.killnetswitch shouldn’t be publishing exact particulars in an effort to attenuate any additional danger to their data.
It isn’t obligatory to make use of a third-party service to use for a U.Ok. digital journey authorization, until you’re retaining an immigration lawyer, and candidates ought to apply by means of the U.Ok. authorities’s web site.
While you buy by means of hyperlinks in our articles, we could earn a small fee. This doesn’t have an effect on our editorial independence.



