Victims of Fake ESTA Scams Face Ongoing Fraud Attempts as Personal Data is Resold

James Reilly, Business Correspondent
5 Min Read
⏱️ 4 min read

After falling victim to a fraudulent ESTA application website, British actress Lisa Riley discovered her personal details were not only stolen but also sold to other criminals, resulting in persistent harassment through weekly calls and texts. The scam, which mimics the official US Customs and Border Protection (CBP) portal, highlights a growing trend of data resale schemes that leave victims exposed to continuous fraud attempts.

The Rise of Fake ESTA Websites

Scammers are increasingly replicating government portals to harvest sensitive information, exploiting users’ trust in official-looking sites. Lisa Riley, known for her role in Emmerdale, clicked on a Google search result that led to a near-identical replica of the legitimate ESTA application page. She paid a fee and provided her passport and banking details, only to later discover the confirmation email never arrived. Upon contacting the site’s support, she was directed to a garbled webpage, realising she had been defrauded.

The fake site’s design mirrored the official CBP portal, with subtle differences that could easily go unnoticed. Experts note that criminals often use AI tools to recreate these pages and optimise them for search engines, making them appear legitimate. A CBP spokesperson warned that such sites may pressure applicants into acting quickly, a tactic designed to bypass critical scrutiny.

Personal Data as a Commodity

Once obtained, victims’ data becomes a tradable asset in underground markets. Riley’s ordeal illustrates this cycle: after losing £16 for an ESTA application, she began receiving frequent calls and messages, many impersonating her bank. “Calls are once a week, easy – sometimes twice a week,” she said, her voice tinged with frustration. “And the texts even more often.”

Personal Data as a Commodity

Annya Burskys, head of fraud operations at Nationwide Building Society, explains that criminals repurpose stolen data to craft targeted scams. “They take the personal information they’ve gained and either sell it to other scammers or use it to make follow-up bank impersonation calls, texts, and emails appear more convincing,” Burskys said. Research by Nationwide reveals that 15% of people have unknowingly shared personal details with fraudulent entities, leaving them vulnerable to further exploitation.

Protecting Against Data Resale Scams

To avoid becoming a victim, users must prioritise official channels. The genuine ESTA application is only available on the .gov domain or via the official mobile app. CBP advises applicants to safeguard their confirmation numbers and payment details, retaining records of all transactions. Financial institutions also play a critical role in safeguarding customers, with Nationwide urging users not to feel pressured into action. “A genuine call or message from your bank will never ask you to move money, never ask you to share codes, and will never tell you what to say to your bank or friends, family,” Burskys emphasized.

Should fraud occur, prompt reporting is essential. In the UK, victims should notify their banks and report incidents to Action Fraud. Burskys recommends documenting all suspicious communications and verifying the identity of callers through official channels. “Take a moment to verify who you’re speaking to and contact your bank directly using trusted contact information from your bank card or search for the official website if you’re unsure,” she advised.

Why it Matters

The resale of stolen data underscores a darker aspect of the digital economy, where personal information becomes a commodity fueling chains of exploitation. For victims like Riley, the consequences extend far beyond the initial financial loss, creating months or years of harassment and anxiety. As criminals refine their tactics using AI and search engine optimisation, the onus falls on individuals and institutions to remain vigilant. This case serves as a stark reminder that safeguarding personal data is not just about preventing a single scam—it’s about protecting oneself from a web of interconnected frauds that can persist long after the initial theft.

Why it Matters
Share This Article
James Reilly is a business correspondent specializing in corporate affairs, mergers and acquisitions, and industry trends. With an MBA from Warwick Business School and previous experience at Bloomberg, he combines financial acumen with investigative instincts. His breaking stories on corporate misconduct have led to boardroom shake-ups and regulatory action.
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *

© 2026 The Update Desk. All rights reserved.
Terms of Service Privacy Policy