Travel security · First person

Here There Be Dragons

I work in information security. I still paid $164 for a £20 UK ETA. The ETA was real. The company did what it said. I just didn't read what I was clicking.

By Greg Tyree  ·  Published September 12, 2026  ·  9 min read

The numbers

£20

Official UK ETA fee, per person

$163.89

What I paid, per person

$327.78

Total for two of us

~$270

More than the government would have charged

Official fee verified at gov.uk/eta on September 12, 2026. Check it yourself before you pay; it has changed before.

Traveling is not for the faint of heart. The Internet is overflowing with stories of pickpockets, price gouging, and scams, and in a lot of cases those stories are true. But what happens when the grift starts before you even step foot on foreign soil? Travel and tourism contributed roughly $11.6 trillion to global GDP in 2025, according to the World Travel & Tourism Council, about 9.8% of the world economy. International visitors alone spent $2.02 trillion getting somewhere and being there. When there is that much money at play, you can rest assured that there are a lot of people out there looking for a way to cash in, often at your expense.

I should know better. I work in information security, and I'm an experienced international traveler. I know what phishing looks like. I know not to blindly trust sponsored search results. I know that a website looking official doesn't make it official. And yet, earlier this year, I managed to pay nearly $164 for a UK Electronic Travel Authorisation (ETA) that I could have bought directly from the British government for £20.

The worst part? Nobody stole my credit card. The ETA wasn't fake. The company actually did exactly what it said it would do.

I just didn't read what I was clicking.

What happened

In July 2026, Stef and I were getting ready for a trip that started with two nights in London before a cruise out of Southampton. The UK now requires American visitors to hold an ETA before boarding, so I sat down one evening to knock it out. Two applications, two approvals, done. I didn't think about it again.

My credit card statement later showed two charges from a merchant called ETA VISA SERVICES, for $163.89 each. The approval emails had all the normal UK ETA information in them. They also came from the company's servers and not from the government. I didn't notice that either. The site I had used was visauketa.com.

And here's the thing: it worked. The ETAs were real. We flew to London, I handed over my passport, UK Border Force waved us through, and we spent two very nice nights at the Park Hyatt on Hyatt points before heading to the ship. Nothing about the trip gave me a single reason to revisit how the paperwork had gone.

How I found out

Months later, I was sketching out another trip that might route through London, and I started looking into an ETA for Jake, my daughter's boyfriend, who'd be joining us. I went to look up the process, and there it was on GOV.UK in plain type: an ETA costs £20.

Wait. I paid way more than that.

Back through the statements. Two lines, $163.89 each, $327.78 total, for something that should have cost about $55 for the pair of us. That's when the security analyst finally showed up for work, roughly two months late, and I started digging into what I had actually bought.

What I found when I went back and read the site

The site was not the UK government. It is run by a private company, which its own footer identifies as Sebe Inc., an "independent travel support company" with a street address in Richmond Hill, Ontario. Its disclaimer page says, in so many words, that it is "not affiliated with, endorsed by, or acting on behalf of any government body, including the UK Home Office." Its pricing page lays out a fee schedule: a £20 government fee, a £99 service fee, and a total of £119, charged in US dollars. At the exchange rate the day I applied, £119 came to $163.89.

This is the part where I need to be precise, because it matters. The company submitted my information to the UK government and obtained two legitimate ETAs. It charged the fee its site lists. It discloses that it is a middleman and that you can apply directly at gov.uk without paying it anything. I authorized both charges. I received the product.

What I did not receive was any value for the £99. There is nothing an intermediary can do for a UK ETA that the ten-minute government form doesn't already do. I paid a very expensive convenience fee for a task that was already convenient, and the information I needed to know that was on the page. I just wasn't reading it. That's the story, and I'm not going to dress it up as something more sinister than it is.

One more thing, for the security nerds like me. When I went back to the site while writing this, Malwarebytes blocked it and categorized it as phishing. That's Malwarebytes' classification, not mine, and I'll leave the label to them. What I can say is that GOV.UK itself now carries a warning on the ETA page: "Other websites may charge more to apply. Avoid websites that imitate government services."

How I got there

This part I do remember. I searched for the UK ETA. The first result was a sponsored link. I clicked it. That's it. That's the whole story of how I ended up on a private company's website instead of the government's. Try the same search today and you'll probably see the same thing: paid results from processing services sitting right above the real GOV.UK link.

Funny story. It happened to me again while I was writing this. I wanted to look at Google's Gemini, so I searched "Gemini AI." In a hilarious twist of fate, OpenAI had sponsored the first link. I hit it without thinking, and instead of going to Gemini I went to ChatGPT. No harm done. But it was the exact same reflex. First result. Click. The only difference between that click and the £99 one was what was waiting on the other side.

Here's the real problem. When you type "UK ETA application" into a search box, you aren't shopping. You aren't asking which company you should hire to get your ETA. You're thinking "take me to the place where I apply." That's what the search people call navigational intent, and it comes with an assumption built in: there's only one place to go. If a company pays its way into that path, you may never realize there was a choice to make. I sure didn't.

Why I never noticed

This is the part I find most interesting, and most uncomfortable. My mental model of the task was simple: I need a UK ETA. Find the application. Fill it out. Pay. Get approved. Fly. Every single event that followed confirmed that model. I got an approval. It looked legitimate. It was legitimate. My passport was authorized. I flew to London. Immigration let me in.

There was never a failure event. Nothing went wrong, so nothing forced me to go back and question the first step. In security work we talk about feedback loops constantly: the alert that fires, the login that fails, the payment that bounces. Those are the moments that make you look again. This had none of them. The only signal was a price, and I didn't know the right price until I happened to look it up for someone else two months later.

The call to Bank of America

I called Bank of America and talked to the disputes team. They were genuinely kind about it. They also told me, correctly, that there wasn't really anything they could do. I authorized the transactions. The merchant provided the service it described. The ETAs were valid and I used them. A chargeback exists to reverse fraud or non-delivery, and this was neither.

That's worth sitting with, because it's what separates this from a conventional card-fraud story. The system worked as designed. The card network, the bank, the merchant, and the UK government all did their jobs. The only component that didn't was me.

The security lesson

Security awareness doesn't make you immune to deception. Sometimes you don't miss the warning signs because you don't know what they look like. You miss them because you aren't looking for them.

I wasn't in security-analyst mode that night. I was in "get this stupid travel requirement done" mode. I wasn't investigating a suspicious email. I wasn't responding to an incident. I was doing paperwork, and paperwork is exactly where your guard is down. Context is part of the attack surface. Expectation is part of the attack surface. Every social engineer on the planet knows this. I teach it.

Now, the security guy who lives in my head has some thoughts about that last sentence. "You teach it. You literally stand in front of rooms full of people and teach it. And you clicked the sponsored link." Yes. I did. Knowing a thing and being immune to it turn out to be two different things, and I'd rather tell you that than pretend otherwise.

There's a second lesson hiding inside the first one. The site did disclose what it was. It did disclose the fee. So someone can reasonably say, "You should have read it." They're right. I didn't. But a disclosure that a trained, motivated reader scrolls straight past is a disclosure that's doing its legal job and not much else. Both of those things are true at the same time. I'll own my half. I'm just not going to pretend the other half doesn't exist.

What to do instead

This goes for the UK ETA, the US ESTA, the Canadian eTA, e-visas, and every other piece of government travel paper. The trap is the same everywhere, and so is the way out.

  • Don't search for the document. Search for the government. Start at the country's official site and click your way to the application. For the UK, that's gov.uk/eta. Period.
  • Read the domain. Not the logo. The domain. Official UK pages end in gov.uk. A domain with "uk" or "eta" or "visa" in it means nothing. Anybody can buy one.
  • Know the price before you ever see a payment form. Look up the official fee first. If the checkout page says something higher, you're on a middleman's site. It doesn't matter what else the page says.
  • Scroll to the footer before you type anything. "Independent." "Third-party." "Not affiliated with any government." "Service fee." Any one of those means close the tab and start over.
  • Slow down for the boring stuff. The tasks you do on autopilot are the ones that get you. Two minutes before the payment step. That's all it would have taken. Two minutes and $270.

If this can happen to a guy who does security for a living and travels all the time, it can happen to you. So the next time you apply for a visa or a travel authorization, take the two minutes. Then put the money you saved toward the trip, because that's the part we're actually here for: how points and miles work, which transfer bonuses are live right now, and what real trips actually cost.

I started this by telling you the Internet is full of stories about pickpockets. Well, here's one more. We made it to London, we made it onto the ship, and we came home with all our stuff. The only pickpocket on the whole trip was me.

Sources, checked September 12, 2026

Quick answers

What is the official UK ETA website?

The only official place to apply is the UK government at gov.uk/eta, either through the "UK ETA" app or the GOV.UK website. Any other domain is a private company, even if it has "eta" or "uk" in the name.

How much does a UK ETA cost?

GOV.UK lists the fee as £20 per person as of September 2026. Check gov.uk/eta for the current price before you pay anything, because the fee has changed before and can change again.

Do I need to use a third-party service to get a UK ETA?

No. The government application takes about ten minutes, and GOV.UK says most decisions arrive within a few days. A third party can only submit the same form on your behalf for an added fee.

Can a third-party company obtain a legitimate UK ETA?

Yes. In my case the intermediary submitted my details to the UK government, the ETA was genuine, and I entered the UK on it. Paying an intermediary does not make the ETA fake; it just makes it expensive.

How can I tell the official application from a private one?

The domain ends in gov.uk, the price matches the fee on gov.uk/eta, and there is no "service fee" line. If a site describes itself as an "independent" or "third-party" service anywhere on the page, it is not the government.