A third-party application website called UK Visa Portal publicly exposed thousands of passports and selfie photos belonging to international travellers this week, following a critical security lapse on its cloud database.
An anonymous whistleblower alerted TechCrunch to the massive security vulnerability, revealing that the site was exposing at least 100,000 highly sensitive documents uploaded by visa applicants. Crucially, the platform operates independently of any official British state channels. On community forums, some users have complained about being misled into paying fees to this private firm rather than using the official GOV.UK website.
Following initial media enquiries, the exposed database was secured overnight into Wednesday. Because of the highly sensitive nature of the leaked files, the initial reporting focused on alerting the public to the ongoing vulnerability while withholding specific technical details to prevent exploitation by malicious actors.
Instead of addressing the security failure directly, the portal’s operators chose to deploy their legal and public relations teams to handle the press. This lack of transparency raises significant concerns regarding whether the company plans to notify affected users or report the breach to international regulators, as mandated by US state and European data protection laws.
How the Cloud Database Left Applicants Exposed
The data leak originated from an open Amazon Web Services (AWS) storage bucket used by the company to store user uploads. Although the bucket did not display a public directory index, individual files remained entirely accessible to anyone who could guess or generate the direct URL. The whistleblower who discovered the flaw noted that a backend software bug on the website made it easy to compile the complete list of stored files.
Verified Identity Leaks and GPS Tracking
TechCrunch verified the authenticity of the data by directly contacting affected individuals, confirming that UK Visa Portal (which also trades under the names UK Visit and ETA-Pass) was indeed the source of the leak. Alarmingly, many of the uploaded selfies contained embedded EXIF metadata. This metadata revealed precise GPS coordinates of where the photos were taken, in some instances pinpointing the exact home addresses of the applicants.
This incident highlights a worrying trend of organisations exposing government-issued identity documents due to simple cloud misconfigurations rather than sophisticated cyberattacks. Such exposures are particularly dangerous given the global rise in digital identity checks and age-verification mandates.
Corporate Silence and Legal Deflection
The website provides no clear protocol for reporting security vulnerabilities, nor does it list any corporate officers. When TechCrunch reached out via the general support email to request a secure channel to share the vulnerability details with management, a support agent provided the email address of Michael Taylor, identified as a manager. Taylor did not respond to the query.
Shortly thereafter, attorneys from the US law firm BakerHostetler and PR representatives from FTI Consulting contacted TechCrunch. However, when asked to prove they were legally authorised to represent the company, the lawyers failed to provide any public records confirming their clients’ identities. Consequently, no specific vulnerability details were shared with them to prevent further risk of exposure.
Once the database was finally secured, partner Ryan Christian of BakerHostetler was asked several key questions regarding the duration of the leak, the cause of the misconfiguration, whether access logs had been audited for unauthorised downloads, and who oversees cybersecurity at the firm. Christian declined to answer.
The portal is reportedly operated by Active Leadgen LLC, an entity claiming to be based in the United Arab Emirates, though this corporate structure has not been independently verified.
Travellers are reminded that using third-party intermediaries is entirely unnecessary for obtaining British electronic travel authorisations. To avoid high fees and security risks, applicants should always apply through the U.K. government’s website.
