A third party website operating as UK Visa Portal left an Amazon S3 bucket unsecured, exposing more than 100,000 UK visa applicants' passport scans and identity selfies due to a backend flaw that made the directory pu... When the security lapse was reported by TechCrunch in May 2026, the site's operator, Active Lead...

Create a landscape editorial hero image for this Studio Global article: What security lapse exposed thousands of U.K. visa applicants' passports and selfies on the UK Visa Portal website, and how did the company. Article summary: A website called **UK Visa Portal** — a third-party service unaffiliated with the official UK government — left an **Amazon S3 bucket containing more than 100,000 passport photos and applicant selfies publicly exposed an. Topic tags: general, general web, user generated. Reference image context from search candidates: Reference image 1: visual subject "A website called UK Visa Portal is publicly exposing the passports and selfie photos of applicants who signed up and paid the site to obtain a U.K immigration visa, TechCrunch has" source context "UK Visa Portal spilled thousands of applicants' passports and selfies ..." Reference image 2: visual subject "A websit
In late May 2026, a security lapse at a third-party visa application service left the highly sensitive identity documents of more than 100,000 people exposed for anyone to find. The website, operating under the name UK Visa Portal, was not connected to the official UK government infrastructure but presented itself as a paid channel for visa assistance . Many applicants, under the false impression they were using an official service, uploaded their passports, biometric photographs, and personal details
. The company's response to the discovery of this breach, however, may have been even more alarming than the leak itself.
According to reporting by TechCrunch, the exposure was caused by a misconfigured Amazon S3 bucket used to store uploaded documents . An anonymous security researcher discovered that a backend flaw on the UK Visa Portal website allowed the full directory of stored files to be enumerated, meaning that the list of contents itself was publicly accessible
. No password or authentication was required to access the files, which included passport scans, identity selfies, and other application data
.
TechCrunch was able to verify the authenticity of the leak by contacting several individuals whose personal data was found among the exposed records, confirming that the documents matched real applications . The scale of the incident was immense: at least 100,000 sensitive documents were believed to be vulnerable
.
The website operated as a completely independent commercial service with no affiliation to the Home Office or GOV.UK . It was reportedly operated by Active Leadgen LLC, a company registered in the United Arab Emirates
. The platform charged fees to assist users with UK Electronic Travel Authorisations (ETAs) and other immigration-related applications—processes that can often be completed by users directly on GOV.UK for free or at a much lower cost
.
The site also lacked an essential feature of any platform handling such sensitive information: a proper point of contact or bug-reporting mechanism for reporting security issues . This absence likely extended the time the data remained exposed, as there was no easy way for researchers or users to flag the problem.
The most controversial aspect of the incident was how the company chose to act—or rather, not act—once the problem was uncovered. When TechCrunch reached out to alert the company and prepared to publish its findings, the report indicated that UK Visa Portal had not fixed the security lapse at the time of publication .
Instead of immediately securing the exposed servers and issuing a public disclosure or user notification, the operator took a different route. Reports confirmed that Active Leadgen LLC dispatched legal representatives in an apparent attempt to threaten TechCrunch over the publication of the story . The bucket was only secured overnight hours after TechCrunch’s story went live—not before publication, and not in response to the ethical disclosure
.
The exposed data set created a serious risk of identity theft and fraud. By combining high-resolution passport scans with verification selfies and potentially GPS metadata, malicious actors could potentially use the data to conduct financial fraud, open accounts, or carry out social engineering attacks . Because many victims had little reason to suspect they were using a non-government service, the exposure came as a shock. The official UK government channel for visa applications remains GOV.UK, and this incident serves as a stark reminder to scrutinize third-party services that request highly sensitive identity documents.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
A third party website operating as UK Visa Portal left an Amazon S3 bucket unsecured, exposing more than 100,000 UK visa applicants' passport scans and identity selfies due to a backend flaw that made the directory pu...
A third party website operating as UK Visa Portal left an Amazon S3 bucket unsecured, exposing more than 100,000 UK visa applicants' passport scans and identity selfies due to a backend flaw that made the directory pu... When the security lapse was reported by TechCrunch in May 2026, the site's operator, Active Leadgen LLC, did not publicly remediate the issue and instead dispatched legal representatives to target the publication rath...
The platform had no formal link to GOV.UK, charged applicants for unnecessary paid "assistance," and lacked any responsible disclosure channel for reporting security flaws.