Skip to content

Active Leadgen

Disclosed May 27, 20264 months ago295 affectedConfirmed

Official notice

Unofficial UK visa portal exposed 100,000 passport and selfie files

A private UK visa application site run by Active Leadgen, not affiliated with the UK government, exposed at least 100,000 applicants' passports, selfies and location metadata through an enumerable Amazon S3 bucket. The bucket was secured after TechCrunch published.

What is known

People affected295 (as reported by the organization)
DisclosedMay 27, 2026
HappenedMay 23, 2026
AttackExposed data
Data exposedGovernment IDs, Biometrics, Location
SectorOther · AE
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
ResearchtotalMay 27
Indiana AGresidents of INJun 252
History of this record
  • 2026-09-25 · source_type: press to official · backfill source
  • 2026-09-25 · source_url: https://techcrunch.com/2026/05/27/uk-visa-portal-spilled-thousands-of-applicants-passports-and-selfies-online-and-hasnt-fixed-the-leak/ to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/DB-Year-to-Date-Report-7_2026.pdf · backfill source
  • 2026-09-25 · status: disclosed to confirmed · backfill source
  • 2026-09-25 · verified_by: empty to in-ag · backfill source
  • 2026-09-25 · verified: 0 to 1 · backfill source
  • 2026-09-25 · records_basis: empty to organization · backfill source
  • 2026-09-25 · records: empty to 295 · backfill source
  • 2026-09-25 · occurred: empty to 2026-05-23 · backfill source
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about Active Leadgen

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.