UK Visa Portal website exposed thousands of passport images and selfies via misconfigured cloud storage (techcrunch.com)
- Over 100,000 passport images and selfies of UK visa applicants exposed via misconfigured Amazon S3 bucket
- Files accessible by direct URL; a bug allowed file enumeration; GPS metadata also exposed
- Company Active Leadgen LLC (UAE) failed to fix the issue, instead sent lawyers and PR firm
- Bucket secured only after TechCrunch publication; questions to company unanswered
"A third-party website, UK Visa Portal (also known as UK Visit and ETA-Pass), exposed over 100,000 passport images and selfies of UK visa applicants due to a misconfigured Amazon S3 bucket. The files were not publicly listed but accessible via direct URLs; a bug on the site allowed listing. The data included GPS location metadata from selfies. The company behind the site, Active Leadgen LLC (UAE), did not respond to security notifications, instead directing lawyers to TechCrunch. The bucket was secured only after TechCrunch published the story."
no comments yet.