Data breach
MYVISAJOBS.COM
- Records
- 132,421
- Breach date
- 14 August 2025Estimated
- Added
- 30 August 2025
What was exposed
2 types of data
- Email addresses1
- Phone numbers1
About this breach
Our investigation team estimates that data tied to MyVisaJobs.com, a US-based immigration information platform, began circulating after an attack on or around August 14, 2025. According to our investigation team, the indexed dataset contains about 132,421 rows of information associated with the site. The Everest ransom group listed MyVisaJobs.com as a victim on its leak site, and independent trackers recorded that listing within days of the estimated attack date. Our team cataloged the listing on August 30, 2025. No group claimed the attack in our catalog, but external trackers attribute the victim posting to Everest.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
August 15, 2025: Ransomware.live recorded the Everest ransom group listing MyVisaJobs.com on its leak site, with an estimated attack date of August 14, 2025.
August 18, 2025: Breachsense published a data breach report naming myvisajobs.com as a victim claimed by Everest.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and phone numbers.
Not every individual is affected by every type of data listed here.
Our investigation team did not confirm exact counts for each data type in this listing. The indexed rows are linked to a site whose users include foreign professionals and employers researching H-1B visas, green cards, and job sponsors. Breachsense, which tracks credential exposure, separately reported that it had indexed credentials for myvisajobs.com accounts from infostealer logs and combo lists, while noting that this credential data is not necessarily connected to the ransomware attack.
What Are the Potential Risks for Affected Individuals?
Exposed email addresses and phone numbers are raw material for targeted scams. Attackers can use them for phishing emails that appear credible because they reference immigration topics such as visa applications or employer sponsorship. People in the immigration process are attractive targets because the topic is high-stakes and time-sensitive.
Phone numbers in a dataset like this can feed smishing, which is phishing by text message, and unwanted robocalls. If attackers combine the leaked contact details with a person's name and employer information, they can craft messages that impersonate immigration consultants, recruiters, or government agencies.
There is also a longer-term risk. Email addresses resurface for years in spam lists and future breaches. A leaked phone number cannot be changed as easily as a password or a card number, so the exposure can follow an affected person well past the initial incident.
Anyone who reused a MyVisaJobs.com password on other accounts faces additional risk from credential stuffing, in which attackers try leaked email and password pairs across many websites. We have not verified that passwords were part of this specific dataset, but reuse makes any contact-data exposure more consequential.
What Should You Do If You Were Affected?
Start with your inbox.
Then take a few practical steps:
Change passwords. If you had a MyVisaJobs.com account, change that password and any other account where you reused it. Use long, unique passwords and a password manager.
Turn on two-factor authentication for your email and any account that matters, especially ones tied to finances or immigration filings.
Treat unexpected messages with suspicion. Be cautious of emails or texts about visa cases, employer sponsorships, or fees, even when they look legitimate. Do not click links in unsolicited messages.
Watch for phishing by text and phone. Do not share case numbers, passport details, or payment information with anyone who contacts you first.
Monitor your accounts. Review account activity for sign-ins you do not recognize.
Because the exposure is contact information, the main defense is vigilance rather than replacement. Verify any immigration-related request through an official channel you look up yourself, not through a link or number someone sends you.
