UK Visa Portal, a third-party (non-government) website charging fees for UK visa applications, publicly exposed at least 100,000 passports, selfie photos, and precise location data via a misconfigured public Amazon S3 bucket. A backend bug allowed enumeration of the bucket's file list. When TechCrunch contacted the company, it responded by sending attorneys from BakerHostetler and a PR firm rather than fixing the issue. The data was eventually secured after TechCrunch published its initial report. The company has not confirmed whether it will notify affected users or regulators as required under data breach notification laws. The incident highlights ongoing risks from cloud storage misconfigurations, particularly as governments expand identity verification requirements.

5m read timeFrom techcrunch.com
Post cover image
230 Impressions