Scammers retarget past victims using details harvested from fake Esta sites

Fake Esta websites are harvesting applicants' personal details and passing them to other criminals, leading to repeated scam calls and texts for months after the original fraud.

Criminals are creating websites that mimic the official US Esta application site, taking a fee and then reusing or selling the personal details supplied by applicants, according to a report published by the Guardian on 4 October 20261. The actor Lisa Riley was caught by one such site after finding it through a Google search and entering her passport, bank and personal details1.

Riley lost £16, described as the cost of an Esta at the time, but the report says she has seen a large rise in scam calls and texts in the 17 months since the fraud1. She describes the volume as "Calls are once a week, easy, sometimes twice a week," adding that the texts arrive even more often1. Callers often claim to be from her bank and ask about a money transfer1.

Research from Nationwide building society cited in the report suggests 15% of people have given personal information to something that later turned out not to be genuine, leaving them exposed to further fraud1. Annya Burskys, head of fraud operations at Nationwide, said criminals retarget people after an initial scam, taking the information gained and either selling it on or using it to make follow-up bank impersonation calls, texts and emails appear more convincing1.

The report says the fake site Riley used looked very similar to the official one and appeared high in search results1. Criminals can use AI to recreate legitimate government sites and often put keywords such as "Esta" in the domain name to appear genuine1. A spokesperson for US Customs and Border Protection said some sites may demand the applicant act quickly, a tactic used to stop people thinking something through1.

The CBP spokesperson said applicants should protect their Esta confirmation number and payment details, keep application records and review financial statements for unauthorised charges, and that suspected fraud should be documented and reported promptly to the applicant's financial institution and appropriate local government reporting channels1. In the UK, the report says, that means telling your bank and Report Fraud1.

Why it matters for households

Anyone who has entered passport, bank or personal details on a site that turns out not to be the official Esta service remains exposed to follow-up fraud long after the original payment, according to the report1. The consequences described are ongoing: repeated calls and texts, often from people claiming to be the victim's bank, continuing for months and in Riley's case 17 months after the fraud1. The financial loss on the Esta itself was small, at £16, but the report's account of retargeting means the details handed over can be used again and again1.

The report says the official Esta site has a .gov address and that a mobile app also exists1. Nationwide's fraud head said people who have handed over details should be alert to unexpected calls, texts or emails, and that a genuine call or message from a bank will never ask someone to move money, share codes, or tell them what to say to their bank, friends or family1. She also said people should not feel pressured to act and should verify who they are speaking to, contacting their bank directly using trusted contact information from their bank card or the official website1.

The 15% figure from Nationwide covers people who have given personal information to something that later turned out not to be genuine, which the report links to a risk of future frauds1. The report does not give a UK-wide total for losses connected to fake Esta sites, and no figure for how many people have been affected has been reported1.

What happens next

No dated next steps, reviews or deadlines are set out in the report1. It directs people who suspect fraud in the UK to their bank and to Report Fraud1.

For more on how these approaches work, see our guides to phishing, vishing and smishing and fake websites and online shopping scams, or the wider scams and fraud guide.

Sources1 cited
  1. ‘They call every week’: the phishing attacks targeting past victims | Scams | The Guardian theguardian.com