UK Visa Portal exposed thousands of applicants’ passports and selfies — then called the lawyers on us


A website called UK Visa Portal publicly exposed thousands of passports and selfie photos of applicants who paid the site to obtain a U.K. immigration visa.

An anonymous person notified TechCrunch about the security lapse, saying that the website was exposing at least 100,000 documents from people who uploaded their passports and selfies to the website as part of the application process.

The website is not affiliated with the U.K. government, and some have complained that they mistakenly paid a fee to this company instead of using the official GOV.UK website.

Read more…
Source:  TechCrunch


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • UK railway stations Wi-Fi affected by cyber attack

    September 26, 2024

    The wi-fi has been hacked at 19 UK railway stations to display a message about terror attacks. Network Rail confirmed that the wi-fi systems at stations including London Euston, Manchester Piccadilly, Liverpool Lime Street, Birmingham New Street, Edinburgh Waverley and Glasgow Central were affected. People reported logging on to the wi-fi at the stations on Wednesday ...

  • ‘Two-factor authentication may have stopped Synnovis cyber attack’

    September 25, 2024

    The cyber attack on pathology provider Synnovis could have been prevented by two-factor authentication, according to Beverley Bryant, strategic advisor in the frontline digitisation team at NHS England. Speaking at the Health Excellence Through Technology (HETT) conference on 24 September 2024, in a session titled ‘Best practice in cyber security: Achieving excellence in the health and ...

  • UK: Cyber incident ‘was an accident – not an attack’

    September 23, 2024

    A cyber incident which forced a council to shut down its IT systems was not an “attack, it was an accident”, it is understood. Tewkesbury Borough Council declared a major incident on 4 September after the incident, which a source said was its “own systems testing its own security”. People selling or buying homes in the ...

  • UK: Customer data exposed in Harvey Nichols data breach

    September 22, 2024

    Luxury British department store has announced that it has been the victim of a data breach, in a notification sent to affected customers. The incident, which the store discovered on 16th September, involved the compromise of sensitive data such as names, email addresses, phone numbers and home addresses. Read more… Source: Computing News Sign up for our Newsletter Related:

  • Sunken superyacht believed to contain watertight safes with sensitive intelligence data

    September 21, 2024

    Specialist divers surveying the wreckage of the $40 million superyacht that sank off Sicily in August, killing seven people including British tech tycoon Mike Lynch, have asked for heightened security to guard the vessel, over concerns that sensitive data locked in its safes may interest foreign governments, multiple sources told CNN. Italian Prosecutors who have opened ...

  • Teenager arrested following cyber attack on Transport for London

    September 13, 2024

    A 17-year-old boy has been arrested following a cyber attack on Transport for London. Hackers may have accessed the bank details and home addresses of at least 5,000 customers, TfL admitted on Thursday. The Information Commissioner has been informed. National Crime Agency officers said they had arrested a teenager from Walsall, in the West Midlands, on ...