{"id":2342,"date":"2025-08-17T20:55:39","date_gmt":"2025-08-17T20:55:39","guid":{"rendered":"https:\/\/ft365.org\/index.php\/2025\/08\/17\/home-office-phishing-scam-targets-uk-immigration-sponsors\/"},"modified":"2025-08-17T20:55:39","modified_gmt":"2025-08-17T20:55:39","slug":"home-office-phishing-scam-targets-uk-immigration-sponsors","status":"publish","type":"post","link":"http:\/\/ft365.org\/index.php\/2025\/08\/17\/home-office-phishing-scam-targets-uk-immigration-sponsors\/","title":{"rendered":"Home Office Phishing Scam Targets UK Immigration Sponsors"},"content":{"rendered":"<div>\n<p><img decoding=\"async\" src=\"https:\/\/ft365.org\/wp-content\/uploads\/2025\/06\/localimages\/32483240-27a8-4f36-ac60-9d465c05a5d5.jpg?width=64&#038;height=64&#038;mode=crop&#038;scale=both&#038;format=webp\" alt=\"Photo of James Coker\" loading=\"lazy\"><\/p>\n<\/div>\n<div id=\"cphContent_pnlArticleBody\">\n<div id=\"layout-94a36855-b0e0-4d93-91f0-9278ac6e8758\" data-layout-id=\"2\" data-edit-folder-name=\"text\" data-index=\"0\">\n<p>An active phishing campaign is impersonating the Home Office to compromise UK organizations licensed to sponsor foreign workers and students.<\/p>\n<p>The sophisticated campaign, which closely mimics official UK Home Office communications and web pages, aims to compromise sponsor license holders\u2019 Sponsorship Management System (SMS) credentials.<\/p>\n<p>The compromised credentials are used to facilitate a range of elaborate immigration fraud schemes, extortion attempts and other monetization schemes, according to an investigation by cybersecurity firm Mimecast.<\/p>\n<p>The most elaborate of these involves creating fake job offers and visa sponsorship schemes, with threat actors observed charging victims between \u00a315,000-\u00a320,000 ($20,186-$26,914) for non-existent employment opportunities.<\/p>\n<p>The attacks target UK organizations holding sponsor licences across all industries and sectors, with particular focus on companies actively managing visa sponsorship programs and regular SMS system users.<\/p>\n<p>\u201cThe threat actors demonstrate advanced understanding of government communication patterns and user expectations within the UK immigration system,\u201d the researchers noted.<\/p>\n<p>Samantha Clarke, threat research engineer at Mimecast, told <em>Infosecurity <\/em>that around 8000 emails related to this campaign were observed in the first half of July 2025. The campaign ramped up in early August, with around 2500 emails sent in the first six days of the month.<\/p>\n<p>On July 10, the Home Office issued\u00a0a notification\u00a0on the Sponsorship Management System (SMS) as well as direct communications to sponsors&#8217; key contacts and authorizing officers, warning of phishing scams that could compromise SMS account security.<\/p>\n<h2><strong>Organizations Sent Fake Home Office Warnings<\/strong><\/h2>\n<p>The campaign begins with target organizations being sent emails containing urgent alerts around SMS notifications or system alerts requiring immediate attention.<\/p>\n<p>SMS is the online tool used by sponsors to manage their license and meet their duties to notify the Home Office of changes in circumstances.<\/p>\n<p>These emails contain a link that direct users to fraudulent login pages designed to prompt them into entering SMS authentication credentials.<\/p>\n<p>The Mimecast report, published on August 12, highlighted common subject lines used in the initial phishing email. These include \u2018A new message has been posted to your Sponsorship Management System\u2019 and \u2018Message Notification from SMS\u2019.<\/p>\n<\/p><\/div>\n<figure id=\"layout-6249cc19-8672-440d-9b02-b9d00d176e96\" data-layout-id=\"4\" data-edit-folder-name=\"image\" data-index=\"1\"><img decoding=\"async\" src=\"http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/localimages\/8a7424b1-0c7f-4676-ab66-13c687c84d5a.png\" alt=\"Example urgent warning phishing email impersonating the UK Home Office. Source: Mimecast\"><figcaption>Example urgent warning phishing email impersonating the UK Home Office. Source: Mimecast<\/figcaption><\/figure>\n<div id=\"layout-74ad740c-8af9-404d-9153-bddb1cedc7fc\" data-layout-id=\"2\" data-edit-folder-name=\"text\" data-index=\"2\">\n<p>When the link on the initial email is clicked, the user is first sent to a CAPTCHA-gated URL, which acts as a filtering mechanism. They are then redirected to a phishing page that closely replicates the authentic SMS interface.<\/p>\n<p>The researchers said this replication is achieved through direct copying of the official SMS login page HTML, hotlinking of official assets and minimal but critical changes to the form submission process.<\/p>\n<p>The user credentials, once inputted, are sent to an attacker-controlled script rather than the legitimate authentication system.<\/p>\n<\/p><\/div>\n<figure id=\"layout-072789c0-e158-4ead-bfab-16f4809fb44e\" data-layout-id=\"4\" data-edit-folder-name=\"image\" data-index=\"3\"><img decoding=\"async\" src=\"http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/localimages\/ac7b2806-a96f-4dd5-9f75-ac03873def38.png\" alt=\"The fake SMS log in page. Source: Mimecast\"><figcaption>The fake SMS log in page. Source: Mimecast<\/figcaption><\/figure>\n<div id=\"layout-c0c85f55-9532-44a1-bc2f-0476e07803bc\" data-layout-id=\"2\" data-edit-folder-name=\"text\" data-index=\"4\">\n<h2><strong>Follow-on Immigration Fraud and Extortion Schemes<\/strong><\/h2>\n<p>Once the attackers have captured the SMS credentials, they engage in a range of monetization schemes.<\/p>\n<p>These include:<\/p>\n<ul>\n<li>Selling access to compromised accounts on dark web forums<\/li>\n<li>Conducting extortion schemes against affected organizations<\/li>\n<li>Facilitating fraudulent Certificate of Sponsorship (CoS) issuance<\/li>\n<li>Creating fake job offers and visa sponsorship schemes via seemingly legitimate visa documents<\/li>\n<\/ul>\n<p>Mimecast advised UK organizations holding sponsor licenses to deploy anti-phishing tools that can detect government impersonation attempts and suspicious URL patterns.<\/p>\n<p>Additionally, firms should implement URL rewriting and sandboxing to analyze links before user interaction takes place.<\/p>\n<p><em>Image credit:\u00a0James Copeland \/ Shutterstock.com<\/em><\/p>\n<\/p><\/div>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>An active phishing campaign is impersonating the Home Office to compromise UK organizations licensed to sponsor foreign workers and students. The sophisticated campaign, which closely mimics official UK Home Office communications and web pages, aims to compromise sponsor license holders\u2019 Sponsorship Management System (SMS) credentials. The compromised credentials are used to facilitate a range of<\/p>\n","protected":false},"author":2,"featured_media":2343,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2342","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"featured_image_urls":{"full":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2342-e0de2fe5-67c3-45f7-8d7e-741794c5cf42.jpg",300,300,false],"thumbnail":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2342-e0de2fe5-67c3-45f7-8d7e-741794c5cf42-150x150.jpg",150,150,true],"medium":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2342-e0de2fe5-67c3-45f7-8d7e-741794c5cf42.jpg",300,300,false],"medium_large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2342-e0de2fe5-67c3-45f7-8d7e-741794c5cf42.jpg",300,300,false],"large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2342-e0de2fe5-67c3-45f7-8d7e-741794c5cf42.jpg",300,300,false],"1536x1536":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2342-e0de2fe5-67c3-45f7-8d7e-741794c5cf42.jpg",300,300,false],"2048x2048":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2342-e0de2fe5-67c3-45f7-8d7e-741794c5cf42.jpg",300,300,false],"morenews-featured":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2342-e0de2fe5-67c3-45f7-8d7e-741794c5cf42.jpg",300,300,false],"morenews-large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2342-e0de2fe5-67c3-45f7-8d7e-741794c5cf42.jpg",300,300,false],"morenews-medium":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2342-e0de2fe5-67c3-45f7-8d7e-741794c5cf42.jpg",300,300,false],"crawlomatic_preview_image":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/08\/2342-e0de2fe5-67c3-45f7-8d7e-741794c5cf42-146x146.jpg",146,146,true]},"author_info":{"display_name":"henry","author_link":"http:\/\/ft365.org\/index.php\/author\/henry\/"},"category_info":"<a href=\"http:\/\/ft365.org\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","_links":{"self":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/2342","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/comments?post=2342"}],"version-history":[{"count":0,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/2342\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media\/2343"}],"wp:attachment":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media?parent=2342"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/categories?post=2342"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/tags?post=2342"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}