Employer
Advisory
Work Permits

SMS Security Reminder – Protecting Your Sponsorship Management System Account

The Home Office has issued a reminder to licensed sponsors regarding cyber security risks affecting the Sponsorship Management System (SMS).

Sponsors have been advised that phishing emails continue to circulate, where threat actors attempt to impersonate the Home Office and ask SMS users to log in via links contained in the email. These messages often claim that urgent action is required to avoid compliance issues or to review new SMS notifications.

The Home Office has confirmed that it will never send links for sponsors to log in to their SMS account via email. Sponsors should therefore treat any such messages with caution.

Phishing emails are designed to capture login credentials and may compromise sponsor accounts if users attempt to sign in through malicious links.

Practical notes for employers

Employers should ensure that Level 1 and Level 2 SMS users only access the system directly through the official GOV.UK website and do not click on login links contained in emails. Sponsors may also wish to regularly review SMS user access, ensure passwords and login details are not shared, and deactivate accounts where users no longer require access or have left the organisation.

Employers should remain vigilant and treat any unexpected emails requesting SMS login details with caution.

This update is intended as a general guide and does not replace tailored legal advice. If you have questions regarding SMS security or sponsor compliance responsibilities, please do not hesitate to contact us.