Companies House flaw exposes millions of UK businesses
Companies House flaw exposes millions of UK businesses

A major security flaw at Companies House, the UK's official corporate register, has exposed the private details of directors at millions of businesses. The vulnerability forced the shutdown of its online filing service last Friday, which was restored on Monday after the issue was fixed.

The bug allowed users of the WebFiling system to view specific data from approximately five million registered companies, including directors' dates of birth and residential addresses. It also enabled logged-in users to change some elements of another company’s details, such as addresses and emails, without consent.

The flaw was first discovered by John Hewitt from corporate services provider Ghost Mail. It could be exploited simply by pressing the back key four times while viewing a registered company on the WebFiling system. An internal investigation indicates the issue arose after an October update to the system.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

Andy King, chief executive officer of Companies House, said: “We are asking all companies to check their registered details and filing history to make sure everything appears correct.” He added that there was no evidence of data being accessed or changed without permission, though investigations are ongoing.

The incident is under review by the Information Commissioner’s Office (ICO) and the National Cyber Security Centre (NCSC). An ICO spokesperson advised business owners to view guidance on its SME advice hub, while Companies House has urged any potentially impacted businesses to raise a complaint.

Pickt after-article banner — collaborative shopping lists app with family illustration