Civil society groups have called on the UK's Information Commissioner's Office (ICO) to investigate the Home Office's digital-only eVisa scheme, citing systemic data errors and design flaws that have led to breaches of sensitive personal information and left migrants unable to prove their lawful status. The complaints highlight operational failures, such as the wrongful disclosure of personal data and the lack of effective support for users locked out of their accounts, raising concerns about the scheme's compliance with GDPR and its impact on vulnerable populations who may be digitally excluded.
Separately, the US State Department has implemented a policy requiring H-1B visa applicants and their dependents to make their social media profiles public before consular interviews, exposing them to significant privacy and security risks. This move, intended to facilitate online presence reviews for national security vetting, affects hundreds of thousands of skilled workers and their families, many of whom are employed in sensitive industries. Critics warn that this forced digital exposure increases the risk of doxxing, surveillance, and exploitation by malicious actors, while also raising broader concerns about the erosion of privacy rights for immigrants.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The US State Department introduced a policy requiring H-1B visa applicants and their dependents to set all social media profiles to public before consular interviews. The requirement is described as taking effect on December 15 and raises privacy and security concerns for more than a million affected people.
The UK Information Commissioner's Office confirmed it had received the letter about the Home Office eVisa scheme and said it would assess the concerns raised. The Home Office had not commented at the time of reporting.
Civil society groups coordinated by the Open Rights Group submitted a complaint urging the UK Information Commissioner's Office to investigate the Home Office's digital-only eVisa rollout for potential GDPR violations. The complaint alleges systemic data errors, design failures, inadequate support, sensitive data exposure, and problems with the scheme's data protection impact assessment and biometric data handling.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.