News

Major Security Flaw at Companies House Exposed Directors’ Private Data and Enabled Potential Company Hijacking

24 March 2026

A security vulnerability in the Companies House WebFiling system was recently identified, allowing logged-in users to access the private dashboard of other registered companies. The issue affected the online service used by companies to file documents and update details.

Discovery and How It Worked

The vulnerability was discovered on March 12, 2026, by John Hewitt (from corporate services provider Ghost Mail). He demonstrated it to Dan Neidle of Tax Policy Associates, who then reported it to Companies House on March 13.

The exploit was straightforward: After logging into one’s own company dashboard and selecting the option to file for another company (by entering its number), pressing the browser’s back button several times bypassed authentication checks. This granted access to the target company’s non-public area.

What Was Exposed

Users could view:

  • Directors’ residential addresses (not shown on the public register)
  • Personal email addresses
  • Full dates of birth

Other non-public company information

In tests (conducted with permission), it was also possible to attempt changes, such as updating a registered office address. The system issued a submission confirmation number and sent related emails, though no unauthorized changes were confirmed to have been successfully processed.

Timeline and Response

Companies House stated the issue likely dated back to an system update in October 2025, meaning it may have existed for around five to six months. Upon notification on March 13, they temporarily suspended the WebFiling service to investigate and apply fixes. Independent testing was completed, and the service was restored by March 16 or 17, 2026.

In their update, Companies House confirmed no passwords were compromised and apologized for the inconvenience. They are reviewing audit logs and potential impacts, though it’s unclear if they can identify every accessed company.

Potential Implications

The exposure of private director details could increase risks of identity fraud, phishing, or attempts at unauthorized company changes (e.g., for fraudulent purposes like loans). However, no confirmed cases of exploitation or successful fraudulent filings have been reported so far. The incident may lead to scrutiny under UK GDPR rules for personal data breaches, potentially requiring notifications if widespread harm is identified.

Recommendations for Businesses

Directors and company owners are advised to:

  • Log in to their Companies House account and review all details for accuracy.
  • Check recent filings or changes.
  • Remain vigilant for any unusual contact or phishing attempts using personal information.

This case highlights the importance of robust authentication in public-facing government systems that handle sensitive business data.

×