Phishing Emails targeting licensed sponsors and attempting to gain unauthorised access to the Sponsor Management System account.

Phishing Emails Targeting Licensed Sponsors: How to Protect Your SMS Account

Licensed sponsors should remain alert following an increase in phishing emails designed to gain unauthorised access to the Sponsor Management System (SMS). These emails may allow criminals to access sponsor accounts and fraudulently assign Certificates of Sponsorship (CoS).

With Multi-Factor Authentication being introduced for SMS users, sponsors and their internal teams should be particularly careful when receiving emails about changes to the system or the login process.

What do these phishing emails look like?

Fraudulent emails may claim that a new message or an important update is waiting for you in the SMS. In some cases, the email may threaten compliance action unless you log in through a link provided in the message.

These emails are intended to create urgency and encourage recipients to act without checking whether the communication is genuine. You should never click a link in an unexpected email or provide your SMS account details or personal information in response.

Criminals may also attempt to take advantage of the introduction of Multi-Factor Authentication by sending convincing emails about:

  • SMS security updates
  • Account verification
  • Changes to the login process
  • Messages waiting in the SMS
  • Possible compliance action

What will the Home Office never ask you to do?

Licensed sponsors and SMS users should remember that the Home Office:

  • Will never email you a link to access or log in to the SMS
  • Will never ask for your SMS user ID, password or personal information by email
  • Will not email you to advise that a new message is available on the SMS message board

If an email asks you to follow a link to access the SMS or provide sensitive information, you should treat it with caution.

How can licensed sponsors protect their SMS accounts?

Unauthorised access to the SMS could place your organisation and its sponsor licence at risk. Sponsors should ensure that all Level 1 and Level 2 Users understand the correct security procedures.

To help protect your SMS account:

  • Access the SMS only by navigating directly through the official GOV.UK website
  • Never share your SMS password or user ID with anyone
  • Never disclose personal information, including your date of birth, in response to an email
  • Ensure that every SMS user has their own individual user ID
  • Do not click links contained in unexpected or suspicious emails
  • Regularly review your Level 1 and Level 2 Users
  • Deactivate accounts belonging to users who no longer require access

Individual user accounts are important because they help organisations maintain appropriate control over who can access and use the SMS.

What should you do if you receive a suspicious email?

If you receive an email that you do not believe is genuine, do not click any links or respond with account or personal information. The email should be reported to [email protected].

Sponsors should also share this warning with every Level 1 and Level 2 User in their organisation. This is especially important while enhanced SMS security measures, including Multi-Factor Authentication, are being introduced.

Remaining vigilant and following the correct login procedures can help protect your organisation from unauthorised SMS access and the fraudulent assignment of Certificates of Sponsorship. If your organisation requires assistance with its sponsor licence or Sponsor Management System responsibilities, please call us on 0203 959 3335 or email us at [email protected].

Scroll to Top