UK organizations with sponsor licenses are now targets in a credential-harvesting phishing campaign. This campaign impersonates the UK Home Office and mimics the Sponsor Management System (SMS) login to steal usernames and passwords. Once attackers gain access, they can issue fraudulent Certificates of Sponsorship (CoS), exploit sensitive immigration workflows, or extort compromised users.
The post U.K. Home Office Impersonation: A Protection Playbook for Sponser-Licensed Orgs appeared first on Security Boulevard.
James Savard
Source: Security Boulevard
Source Link: https://securityboulevard.com/2025/08/u-k-home-office-impersonation-a-protection-playbook-for-sponser-licensed-orgs/?utm_source=rss&utm_medium=rss&utm_campaign=u-k-home-office-impersonation-a-protection-playbook-for-sponser-licensed-orgs