Full Breakdown
Major Data Glitch at Companies House Exposes Sensitive Information
3/17/2026, 6:38:44 AM
Overview of the Incident
A significant security flaw in the UK’s Companies House WebFiling system has raised concerns about potential fraud, as it allowed logged-in users to access and edit sensitive information of other companies. The glitch, which was reported on March 13, 2023, may have exposed personal data, including directors' home addresses, email addresses, and dates of birth, affecting approximately five million registered companies.
Discovery and Response
The vulnerability was initially discovered by John Hewitt from Ghost Mail, who alerted Dan Neidle, founder of Tax Policy Associates. Neidle detailed the exploit in a blog post, explaining that users could access another company's dashboard by simply pressing the back key multiple times after attempting to file for a different company. This flaw led to unauthorized access to sensitive data and the potential for fraudulent modifications to company records.
Upon being notified, Companies House suspended its WebFiling service on March 13 and initiated an investigation. CEO Andy King stated that the issue was likely introduced during a system update in October 2022. The agency reported that while passwords and identity verification data were not compromised, unauthorized filings could have been made.
Official Statements & Guidance
Companies House has communicated its commitment to transparency and security. Andy King expressed regret over the incident, stating, "Companies House takes its responsibility to protect the data entrusted to us extremely seriously." The agency has reported the incident to the Information Commissioner's Office (ICO) and the National Cyber Security Centre (NCSC). Business owners are advised to check their registered details and report any discrepancies.
An ICO spokesperson confirmed receipt of the report and recommended that affected businesses visit their SME hub for guidance. Companies House will email registered addresses with instructions on how to verify their details and what steps to take if they have concerns.
Criticism & Concerns
Experts have raised alarms regarding the implications of the glitch. Neidle emphasized the ease of exploiting the vulnerability, warning that it could lead to significant fraud if left undetected for an extended period. He noted, "Security researchers say 15 days is the average time it takes for a vulnerability to be exploited, and this was a particularly easy vulnerability with no hacking required." The potential for unauthorized changes to company records poses serious security and GDPR implications.
Ongoing Investigation
As the investigation continues, Companies House is working to identify any unauthorized access or changes made during the period of vulnerability. The agency is expected to conduct a retrospective analysis to determine which accounts accessed unrelated company dashboards and whether any filings were attempted.
Conclusion
The Companies House data breach highlights critical vulnerabilities in the UK's corporate registration system. With millions of companies potentially affected, the incident underscores the need for robust security measures to protect sensitive information and maintain public trust in government services. Companies House has pledged to take firm action against any misuse of the system and to enhance its security protocols moving forward.
