
The U.K.’s Companies House, which maintains the registry of all U.K. businesses, has restored its WebFiling service after a temporary shutdown to address a security weakness. This weakness had exposed company information since October 2025.
Dan Neidle, founder of Tax Policy Associates, a non-profit organization, alerted Companies House to the security problem after John Hewitt of Ghost Mail initially discovered the issue but received no response.
“The process involved logging into Companies House, going to your company’s dashboard, selecting the option to “file for another company,” and entering the company number of any of the five million registered companies,” Neidle explained.
“Although an authentication code was required, users could bypass this by using the ‘back’ button, which would then display the target company’s dashboard instead of their own.”
Neidle stated that this flaw had left the data of five million registered companies vulnerable for five months, including the private addresses and contact information of their directors.
Companies House affirmed the security vulnerability on Monday, coinciding with the reinstatement of the online filing service. They acknowledged that the vulnerability was introduced with a system update in October 2025.
The agency stated that the flaw could have been exploited by logged-in users, allowing them to “modify some elements of another company’s details without approval.” Though, the security vulnerability allowed only for data theft and access to company records only one at a time.
“Our investigation has determined that specific company data not typically available on the Companies House register may have been visible to other logged-in WebFiling users,” Companies House stated.
“This may include dates of birth, home addresses, and email addresses. Furthermore, unauthorized filings, such as financial statements or changes of directors, may have been possible on another company’s record.”
The agency stated that user passwords were not affected, and sensitive information used for identity verification, such as passport details, was not accessed during the period the service was vulnerable. They also clarified that “no existing filed documents, accounts or confirmation statements were able to be changed.”
Companies House has notified the U.K. Information Commissioner’s Office (ICO) and the National Cyber Security Centre (NCSC) about the incident and is currently investigating whether the vulnerability was exploited to access or modify any company’s information.
“At this time, we have no reports indicating that any data has been accessed or altered without authorization,” Companies House announced in a statement. “However, our investigation continues, and we will provide further updates as our work progresses. We remain committed to transparency throughout this process.”
#admits #business #companies #compromised #house #information #news #security #the #vulnerability — News
© Bulletproof Servers. All rights reserved.