When the British actor Lisa Riley was preparing to travel to the US last year, she applied online for an Esta so she would not need a visa. After finding the site through a Google search she filled in her passport, bank and personal details and waited for the confirmation, which normally takes just under an hour.
When it failed to arrive, she emailed an address from the site where she had paid and got back a message unlike any she had seen before, with a link to a website that displayed a jumble of words and letters.
It was then she realised she had been scammed. But that was just the start of her problems, which persist to this day. She has been repeatedly targeted by criminals, receiving text messages and calls many times every week.
Riley was the victim of a fraud where criminals create websites similar to the legitimate one run by US Customs and Border Protection (CBP). After fooling unsuspecting applicants they pocket a fee and use the personal details of victims for later scams.
Riley lost £16 – the cost of an Esta back then – but says there has been a huge increase in the number of scam calls and texts she has received in the 17 months since the fraud happened.
Often the person claims to be from her bank with queries about a money transfer. “Calls are once a week, easy – sometimes twice a week,” she says. “And the texts even more often.”
Research from Nationwide building society suggests that 15% of people have given personal information to something who later turned out not to be genuine, leaving them open to future frauds.
“Criminals do sadly retarget people after an initial scam,” says Annya Burskys, head of fraud operations at Nationwide. “They take the personal information they have gained and either sell it on to other scammers or use them to make follow-up bank impersonation calls, texts and emails appear more convincing.”
What it looks like
The fake Esta site that stole Riley’s personal details looked very similar to the official one and showed up high in search results, she says.
“The webpage was absolutely identical so there was nothing that would remotely make me fearful up until [I realised],” she says.
Criminals can use AI to recreate legitimate government sites and will frequently use key words such as “Esta”, in the domain name to try to portray legitimacy.
A spokesperson for the US CBP says some sites may demand action by the applicant quickly, a common tactic by criminals to try to get people to act without thinking something through.
What to do
Only use the official Esta website, which has a .gov address, or the mobile app.
“Applicants should protect their Esta confirmation number and payment details, retain application records, and review financial statements for unauthorised charges,” says the CBP spokesperson.
“Suspected fraud should be documented and reported promptly to the applicant’s financial institution and appropriate local government reporting channels.”
In the UK that means telling your bank and Report Fraud.
If you have inadvertently handed over your personal details you are at risk of future scams, so be alert to unexpected calls, texts or emails, says Burskys.
“Don’t feel pressured to act. A genuine call or message from your bank will never ask you to move money, never ask you to share codes, and will never tell you what to say to your bank or friends, family,” she says.
“Take a moment to verify who you’re speaking to and contact your bank directly using trusted contact information from your bank card or search for the official website if you’re unsure.”
Source: https://www.theguardian.com/money/2026/oct/04/repeat-phishing-attacks-target-past-scam-victims