UK Visa Portal spilled 100,000 passports and selfies — then sicced lawyers on the journalists who found out
A third-party visa service left applicants' most sensitive biometric documents exposed in an unprotected bucket, and its response to reporters was a legal threat.
Written by OutOfToken AI
June 7, 2026 · 4 min read · Synthesized from reporting by DataBreaches.net · How this works
A third-party website trading on the UK immigration process has been publicly leaking the passport scans, selfie photographs, and personal documents of at least 100,000 visa applicants — and as of reporting, the exposure remained unresolved. UK Visa Portal, which charges users fees to navigate British immigration paperwork, left a cache of highly sensitive identity documents accessible without authentication. When TechCrunch's Zack Whittaker contacted the company for comment, the site's response was to dispatch lawyers.
What Was Exposed — and for How Long
The leaked data includes government-issued passport images, biometric selfies submitted as identity verification, and location data tied to individual applicants — precisely the documents that identity thieves and fraudsters most covet. An anonymous tipster brought the exposure to TechCrunch's attention, estimating the accessible file count at over 100,000 records. The data appears to have been stored without access controls, meaning anyone with a direct URL or basic enumeration skills could retrieve documents belonging to real applicants who had paid for the service in good faith. The site is not affiliated with His Majesty's Government or the UK Visas and Immigration service, a distinction it does not make conspicuous to prospective customers.
A Company That Preys on Confusion
UK Visa Portal operates in a crowded grey market of intermediary services that position themselves alongside official government channels, often charging premium fees for form-filling assistance that applicants could complete directly through gov.uk at no cost. These services are not illegal, but they benefit commercially from the complexity and anxiety surrounding immigration applications. Collecting passport-grade identity documents is a legitimate part of many visa workflows — but the obligation to secure that data under the UK GDPR and the Data Protection Act 2018 is unambiguous. Storing biometric imagery and passport scans in an exposed, unauthenticated environment represents a textbook failure of basic cloud hygiene: no bucket policy, no signed URLs, no access logging discipline.
"At least 100,000 passport scans and selfies sat exposed without authentication — and when reporters called, the company called lawyers instead of patching the leak."
The Legal Threat Gambit
Rather than acknowledging the vulnerability, remedying it, and issuing breach notifications to affected users — the legally mandated sequence under UK GDPR, which requires notifying the Information Commissioner's Office within 72 hours of becoming aware of a qualifying breach — UK Visa Portal chose to involve legal counsel against the outlet that discovered the problem. That decision both deepened the reputational damage and raised immediate questions for the ICO. Regulating bodies take a dim view of companies that respond to breach disclosures with suppression tactics rather than containment. The ICO has authority to issue fines of up to £17.5 million or four percent of global annual turnover for serious infringements, and the combination of inadequate security controls and a failure to self-report is precisely the profile that draws maximum regulatory scrutiny.
For the applicants whose passports are now floating in an unsecured exposure, the path forward is grim: there is no replacing a biometric passport once its image is in criminal hands, and the threat of identity fraud or synthetic identity creation from such a dataset is enduring, not episodic. The ICO should be investigating. UK Visa Portal should be issuing breach notifications. And every person who uploaded documents to the service should be treating their passport as compromised until proven otherwise. The broader lesson is one regulators have been slow to enforce: a company that collects government-grade identity documents assumes government-grade responsibility for protecting them — no matter how small the startup, or how thick the legal brief.
Editorial Note
This story was originally reported by Zack Whittaker at TechCrunch, a reputable technology publication with strong investigative journalism credentials. DataBreaches.net is a legitimate aggregator of security breach information operated by privacy advocate Kelly Sheridan. However, the headline appears to describe an ongoing vulnerability, and verification depends on whether the breach has been independently confirmed by UK authorities or the actual visa portal operator.
Claim Tracker
AI-assessed
Based on anonymous tipster estimate; no independent confirmation of exact number provided in article
Described but no technical evidence or proof-of-concept details provided
Stated as fact but no pricing or business model documentation cited
Implied in headline and article but specific legal communication not detailed
Standard clarification for third-party immigration service providers
Ask AI about this story
// discussion
sign in to join the discussion