VFS Global Faces Scrutiny Over Data Security Issues in Visa Processing
Article Content
- •VFS Global is under investigation for data security issues at its visa processing centres.
- •Biometric data of applicants was found stored unencrypted and shared insecurely.
- •The company denies wrongdoing and claims to operate under strict government oversight.
VFS Global, the world's largest visa outsourcing company, is under scrutiny following an investigation by Lighthouse Reports that revealed serious data security concerns at its visa centres across Europe. The investigation reviewed 150 inspection reports from 20 EU member states, highlighting that applicants' biometric data was stored on unencrypted devices and shared through unsecured email systems. This raises significant risks for the personal information of millions of visa applicants, particularly over one million Indians applying for Schengen visas annually. Additionally, issues of 'visa shopping' and fraudulent appointment bookings were noted, although these were primarily linked to third-party agents rather than VFS Global itself. The company has denied the allegations, asserting that it operates under strict oversight and that all optional services are clearly communicated to applicants. The scrutiny reflects broader concerns about the privatization of visa processing and its implications for data security and applicant experience.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track VFS Global in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…