Observed Signal · May 27, 2026 · Data Breach · Source: techcrunch · Impact: 3/5 · Sentiment: Negative
UK Visa Portal Exposed Thousands' Passports and Selfies
A third-party site called UK Visa Portal publicly exposed thousands of passport images, selfies and location data uploaded by customers seeking U.K. immigration visas. An anonymous tipster told TechCrunch the site exposed at least 100,000 documents; TechCrunch verified the leak and contacted affected individuals. The exposure was caused by files hosted on an Amazon storage bucket that were accessible via direct file URLs, and many images contained precise location (EXIF) data. TechCrunch says the bucket was secured hours after publication. UK Visa Portal did not provide direct management contacts and referred TechCrunch to attorneys and a PR firm; the company is allegedly run by Active Leadgen LLC based in the UAE. It is not affiliated with the U.K. government.
Large-scale exposure of sensitive identity documents and embedded location metadata raises regulatory, consumer-trust and identity-verification risks; highlights misconfiguration risks in cloud storage used by third-party identity services.
Track Amazon Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- At least 100,000 user documents (passports, selfies) were exposed according to an anonymous source.
- Exposed files were hosted on a publicly accessible Amazon-hosted storage server (S3 bucket) reachable via direct file URLs.
- Many uploaded photos contained precise location data (EXIF) that could reveal users' real-world addresses.
- TechCrunch verified the data and reported the issue; the bucket was secured hours after TechCrunch's initial story.
- UK Visa Portal engaged attorneys (BakerHostetler) and PR firm FTI Consulting instead of directly fixing or responding publicly; the service is allegedly run by Active Leadgen LLC.
Connected Companies & Entities
1 Entity mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Hotel check-in system exposed over one million IDs
A Japan-based hotel check-in system called Tabiq, maintained by startup Reqrea, left more than one million passports, driver’s licenses and selfie verification photos publicly accessible after a cloud storage misconfiguration. Independent researcher Anurag Sen discovered the exposed files in an Amazon-hosted storage bucket named "tabiq" and alerted TechCrunch; Reqrea secured the bucket after being notified and engaged external counsel while JPCERT was also contacted. The bucket contained records dating from early 2020 through May 2026 and was indexed by GrayHatWarfare. Reqrea says it is investigating the scope of the exposure and plans to notify affected individuals. The incident highlights recurring risks from cloud misconfigurations in identity-verification and KYC workflows.
Hackers suspected of breaching ID verification service IDScan
Independent security journalist Brian Krebs reported that a dark web identity search site called Nexus is advertising access to more than 150 million driver's licenses and passports from the US and Canada, apparently stolen from a major identity verification company. Krebs identified the likely source as IDScan, a Louisiana-based ID verification service used by major tech and consumer brands. The site claimed to add about 500,000 new documents daily, suggesting near real-time access to the company's systems. Krebs confirmed his own driver's license was in the database, and Defense Secretary Pete Hegseth's photo was also listed. IDScan's COO said the company is investigating, and the FBI's New Orleans field office is probing the breach. Nexus went offline after the report was published.
Duc App Exposed Hundreds of Thousands of ID Documents
A publicly accessible Amazon-hosted storage server containing unencrypted identity documents and personal data collected by the Duc App (owned by Toronto-based Duales) was exposed to the open web. Security researcher Anurag Sen of CyPeace discovered the misconfigured storage server listing over 360,000 files that included driver’s licenses, passports, selfies, and spreadsheets with names, addresses and transaction details. TechCrunch alerted Duales’ CEO Henry Martinez González, after which the files were made inaccessible; a listing of the server contents remained visible. The company said the data was on a "staging site." Canada’s privacy regulator has reached out to Duales for more information. The exposure dated back to September 2020 and the Duc Android app shows over 100,000 downloads on Google Play.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
