discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

UK Visa Portal spilled thousands of applicants' passports and selfies online — and hasn't fixed the leak

TechCrunch found UK Visa Portal exposing passport scans and selfie photos from applicants, with the leak still unfixed after being reported.

By Zack Whittaker·May 26·techcrunch.com·2 min read

Intelligence analysis by GPT-5.4 Mini

TechCrunch says UK Visa Portal publicly exposed sensitive identity documents from people who used the site to apply for a U.K. immigration visa. The company allegedly had no clear security-reporting path, and the leak remained open after TechCrunch tried to alert management.

Why it matters

This is a direct privacy and identity-theft risk for applicants who shared passports and face photos with a third-party service they may have mistaken for an official government site. It also raises questions about how private visa intermediaries handle highly sensitive personal data.

A website that was supposed to help people with visa forms left private papers sitting out where other people could see them. Those papers included passport pictures and face selfies, which are very personal.

Think of it like putting a stack of locked folders on a table instead of in a cabinet. Anyone walking by could peek at them, copy them, or use them in the wrong way.

The story matters because passport details can be used to steal someone’s identity. TechCrunch says the website knew about the problem, but the leak still had not been fixed when the article was written.

Analysis

What happened

TechCrunch says it found a security lapse on a site called UK Visa Portal that was publicly exposing passports and selfie photos submitted by visa applicants. The people affected had paid the site to help with a U.K. immigration visa process, and TechCrunch says the exposed material included at least 100,000 documents.

Why the exposure is serious

The leaked files are especially sensitive because they combine identity documents with face photos. TechCrunch says it verified the authenticity of the exposed data by contacting affected individuals and asking whether the information matched their own records. That verification step suggests the exposed files were not random noise but real applicant data.

Response and status

According to TechCrunch, the site is not affiliated with the U.K. government, and some applicants reportedly thought they were paying for an official service instead of using GOV.UK. TechCrunch says it tried to warn the company, first through the address listed on the site and then through people described as its attorneys and PR firm, but did not hear back from management. The article says the leak was still not fixed at publication time.

What readers should take away

TechCrunch’s main warning is practical: applicants do not need a third-party service to apply for a U.K. electronic travel authorization unless they are using an immigration attorney, and they should apply through the government website instead. The story is framed as an active security issue rather than a historical breach, which makes the unresolved exposure the central concern.

Key points

  • TechCrunch says UK Visa Portal was exposing passport scans and selfie photos online.
  • The article says the exposed set included at least 100,000 documents.
  • TechCrunch says it verified the data by checking with affected people.
  • The site is described as not being part of the U.K. government.
  • TechCrunch says the leak was still ongoing when the story ran.

Originally reported at

techcrunch.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritysocietypolicytechglobal-news

Author

Zack Whittaker

Intelligence analysis by

GPT-5.4 Mini

Published

May 26, 2026

Source

techcrunch.com

Share

Topics

securitysocietypolicytechglobal-news

Related

More from this desk

Jul 29·engadget.com

Pokémon Pokopia's First DLC Comes To Switch 2 On August 5

Pokémon Pokopia's first DLC, Bubbly Basin, arrives on August 5, introducing an underwater area to explore and a new Dive move. The update is part of the Pokémon Pokopia Expansion Pass, which costs $35.

Jul 29·9to5google.com

Galaxy Z Fold 8 gives apps new scaling options for its large displays

Samsung's Galaxy Z Fold 8 gets a new feature in One UI 9 that allows users to adjust the zoom level of individual apps on the large display. This feature is currently in beta and can be enabled in Samsung Labs.

Jul 29·techcrunch.com

Elon Musk’s X settles multiyear legal battle with the World Federation of Advertisers

Elon Musk's X has settled its multiyear legal battle with advertising trade group the World Federation of Advertisers (WFA). The settlement ends Musk's aggressive attempt to hold advertisers legally responsible for pulling spending from X over brand safety concerns.

Jul 29·9to5google.com

Samsung has restocked Galaxy Z Fold 8’s popular ‘Pistachio’ color, shipping in August

Samsung has restocked the Galaxy Z Fold 8 in the popular 'Pistachio' color, with shipping dates moved up to August. The device was previously delayed due to a sell-out and shipping issues.