A third-party site called UK Visa Portal publicly exposed sensitive immigration application records, including passport images and selfie photos uploaded by people seeking U.K. visa-related services. Reporting said at least 100,000 documents were accessible online, and affected records were verified as authentic. The site is not affiliated with the U.K. government, but some applicants reportedly used it and paid for its services instead of submitting documents through the official GOV.UK portal. Efforts to alert the company were hampered by the absence of a clear security contact or identified management, and the exposure reportedly remained unresolved.
Separate reporting highlighted a similar identity-data exposure involving AU10TIX, an identity verification provider used by major platforms including TikTok, X, and reportedly Uber. Researchers found exposed credentials that allegedly allowed access to logs containing names, dates of birth, nationalities, identification numbers, document types, and uploaded images of government-issued IDs such as driver’s licenses. The incident drew renewed scrutiny to outsourced age and identity verification systems, which concentrate highly sensitive personal data and can increase the risks of identity theft, phishing, blackmail, and loss of anonymity when security controls fail.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
TechCrunch reported that the UK Visa Portal exposure was secured hours after its initial story was published. The company did not directly explain the remediation and continued routing communications through attorneys and a public relations firm.
As of the reporting, the UK Visa Portal data exposure had not been fixed and sensitive applicant documents were still publicly accessible. Coverage noted the site was not affiliated with the U.K. government and reiterated advice for applicants to use the official GOV.UK service instead.
After identifying the exposure, TechCrunch tried to notify UK Visa Portal, but said the site lacked a clear security reporting channel and did not identify its management. The publication reported receiving replies from purported attorneys and a public relations firm rather than company leadership.
TechCrunch verified that UK Visa Portal was publicly exposing sensitive applicant documents, including passport images and selfie photos submitted for U.K. visa-related services. An anonymous source told the publication that at least 100,000 documents were exposed, and TechCrunch confirmed the authenticity of the leaked records by contacting affected individuals.
A researcher used the exposed AU10TIX credentials to access the company's logging platform and found links to highly sensitive identity records, including uploaded government IDs. Reporting said the researcher demonstrated access to data associated with identity checks for major online platforms and services.
A reported security exposure left AU10TIX login credentials publicly accessible for more than a year, enabling access to the company's logging platform and sensitive identity verification records. The exposed data reportedly included names, dates of birth, nationalities, identification numbers, document types, and uploaded ID images tied to services used by platforms such as TikTok and X.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcetechcrunch.com
Open sourcetechcrunch.com
Open sourcereddit.com
Open sourcedarkreading.com
Open sourceeff.org
Open source404media.co
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.