Active Leadgen
Disclosed May 27, 20264 months ago295 affectedConfirmed
Unofficial UK visa portal exposed 100,000 passport and selfie files
A private UK visa application site run by Active Leadgen, not affiliated with the UK government, exposed at least 100,000 applicants' passports, selfies and location metadata through an enumerable Amazon S3 bucket. The bucket was secured after TechCrunch published.
What is known
| People affected | 295 (as reported by the organization) |
|---|---|
| Disclosed | May 27, 2026 |
| Happened | May 23, 2026 |
| Attack | Exposed data |
| Data exposed | Government IDs, Biometrics, Location |
| Sector | Other · AE |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| UK visa portal spilled thousands of applicants' passports and selfies onlinetechcrunch.com · News | News |
| Indiana Attorney General 2026 data breach report: Active Leadgenin.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | May 27 | |
| Indiana AGresidents of IN | Jun 25 | 2 |
History of this record
- 2026-09-25 · source_type: press to official · backfill source
- 2026-09-25 · source_url: https://techcrunch.com/2026/05/27/uk-visa-portal-spilled-thousands-of-applicants-passports-and-selfies-online-and-hasnt-fixed-the-leak/ to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/DB-Year-to-Date-Report-7_2026.pdf · backfill source
- 2026-09-25 · status: disclosed to confirmed · backfill source
- 2026-09-25 · verified_by: empty to in-ag · backfill source
- 2026-09-25 · verified: 0 to 1 · backfill source
- 2026-09-25 · records_basis: empty to organization · backfill source
- 2026-09-25 · records: empty to 295 · backfill source
- 2026-09-25 · occurred: empty to 2026-05-23 · backfill source
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Indiana AG. Record counts are as reported. Not legal advice.