UK Visa Portal Exposes Thousands of Applicants’ Passports and Selfies, Then Issues Legal Warning
TechCrunch has uncovered that a site called UK Visa Portal has inadvertently leaked thousands of passport and selfie images from individuals who have applied for a U.K. immigration visa.
An anonymous source alerted TechCrunch to this security lapse, indicating that the site had accumulated at least 100,000 documents submitted by users during the visa application process, which included their passports and selfies.
This website is not linked to the U.K. government, with some users mistakenly paying fees to this company instead of visiting the official GOV.UK site.
After our initial report, the exposed data was secured overnight into Wednesday. Due to the sensitive nature of the information, TechCrunch recognized the ongoing security concern but opted not to disclose specific details to safeguard individuals’ privacy.
TechCrunch has not yet received a response from UK Visa Portal management. Rather than addressing the situation directly, the company instructed its attorneys and PR representatives to communicate with us.
This incident underscores a growing trend of companies inadvertently exposing customers’ sensitive government-issued identity documents, typically due to misconfigurations instead of external cyber threats. Such breaches are particularly alarming as online identity verification becomes ubiquitous globally, spurred by new age verification regulations.
The company’s lack of communication raises concerns about whether it will notify affected individuals about the public exposure of their passports or inform regulators as required by U.S. state and European data breach notification laws.
Exposed passports, selfies, and location data
The data exposure stemmed from a publicly accessible Amazon-hosted storage server (referred to as a bucket), where UK Visa Portal keeps user-uploaded passports and selfies.
While the bucket did not publicly display its contents, the files were still accessible to anyone with the correct web address. The whistleblower informed us that a flaw in the UK Visa Portal’s backend allowed them to view the contents of the bucket.
TechCrunch confirmed that UK Visa Portal (also known as UK Visit and ETA-Pass) was indeed the source of the leak and validated the authenticity of the exposed data by directly contacting affected individuals.
Numerous uploaded images included precise location data, indicating where the photos were taken; in some cases, this information was detailed enough to reveal the image owner’s home address.
UK Visa Portal does not provide a way to report security issues on its website and lacks identifiable names or contact information for its management. TechCrunch used the email address provided on the UK Visa Portal site to inform them about the security challenge and inquire whom in management we could contact for details. Given the nature of the exposed data, we could not share specifics through the general customer support channel.
A customer support representative supplied TechCrunch with the name and email of a manager, Michael Taylor, but he did not respond to our inquiries.
Shortly after, attorneys from the U.S. firm BakerHostetler and representatives from the PR firm FTI Consulting contacted us for information about the UK Visa Portal matter. When TechCrunch asked, the attorneys did not provide proof of their authority to represent the company, such as official records validating the individuals’ names and roles. We reiterated that we could only share information concerning the security breach with someone in management.
We proposed that if Taylor or another manager wanted to address the security issue, they should get in touch or involve the attorneys in the email thread. A response was not received.
After our article was published and the bucket was secured, TechCrunch sent a series of questions to the attorneys about the security breach, including how long the Amazon-hosted bucket was exposed, the cause of the exposure, and whether logs exist indicating if anyone accessed or downloaded the exposed data. We also inquired about who at UK Visa Portal is responsible for cybersecurity, if anyone. Christian did not respond.
UK Visa Portal is reportedly run by a company named Active Leadgen LLC, which claims to be based in the United Arab Emirates; however, TechCrunch could not independently verify this information.
Engaging a third-party service to apply for U.K. electronic travel authorization is unnecessary unless consulting an immigration attorney; applicants should utilize the official U.K. government website.
Originally published on May 26 and updated with further details about the security breach.
When you click links in our articles, we may earn a small commission. This does not affect our editorial independence.


