VulnerabilitiesHIGH

UK's Companies House - Security Flaw Exposed Business Data

🎯

Basically, a security issue let people see other companies' private information.

Quick Summary

A serious security flaw at Companies House exposed sensitive data of five million companies for five months. This raises significant concerns about data protection and privacy. Companies House is investigating the incident and has reported it to the relevant authorities.

What Happened

In a recent revelation, Companies House, the U.K. government agency responsible for the corporate registry, confirmed a significant security flaw in its WebFiling service. This vulnerability, discovered by John Hewitt and reported by Dan Neidle, allowed logged-in users to access the dashboards of other companies. The issue persisted for five months, exposing sensitive information of approximately five million registered companies.

The flaw was introduced during a system update in October 2025. Users could log in to their accounts and, by entering another company's registration number, inadvertently access that company's dashboard. This situation arose when users pressed the back button, leading them to a dashboard that did not belong to them, revealing potentially sensitive data.

Who's Affected

The exposure affects all entities registered with Companies House, which includes limited companies, partnerships, and sole traders across the U.K. The data at risk includes management's home addresses, email addresses, and other personal information. While Companies House has assured that no passwords or sensitive identity verification data were compromised, the vulnerability raises serious concerns about the integrity of the data held by government agencies.

As investigations continue, Companies House has reported the incident to the U.K. Information Commissioner's Office (ICO) and the National Cyber Security Centre (NCSC). They are currently assessing whether any unauthorized access or alterations occurred during the vulnerability period.

What Data Was Exposed

The security flaw allowed unauthorized visibility of specific data that is typically not made public. This included:

  • Dates of birth of company directors
  • Residential addresses
  • Company email addresses

Additionally, there were concerns that unauthorized filings could have been made, such as changes to directors or financial accounts. Companies House has emphasized that while the flaw could have been exploited, they have no confirmed reports of unauthorized access or alterations at this time.

What You Should Do

If you are a business owner or stakeholder registered with Companies House, it is crucial to remain vigilant. Here are some recommended actions:

  • Monitor your company’s information on the Companies House register for any unauthorized changes.
  • Review your security practices, especially regarding sensitive information shared online.
  • Stay informed about updates from Companies House regarding this incident and any potential impacts on your data.

As Companies House continues to investigate, they have committed to transparency and will provide updates as more information becomes available. It is essential for all registered companies to understand the implications of this vulnerability and take proactive steps to safeguard their data.

🔒 Pro insight: The prolonged exposure of sensitive data highlights critical weaknesses in governmental data protection protocols, necessitating immediate reforms.

Original article from

BleepingComputer · Sergiu Gatlan

Read Full Article

Related Pings

HIGHVulnerabilities

Microsoft Edge Vulnerability - Critical Update Released

Microsoft has released a critical update for Edge to fix CVE-2026-3910. Users must update to version 146.0.3856.59. This vulnerability poses serious risks, so immediate action is essential.

Canadian Cyber Centre Alerts·
HIGHVulnerabilities

Vulnerabilities - CISA Adds CVE-2025-47813 to Catalog

CISA has added a new vulnerability to its catalog, CVE-2025-47813. This flaw affects the Wing FTP Server and poses serious risks to federal networks. Timely remediation is crucial to prevent exploitation. Organizations are urged to prioritize addressing this vulnerability.

CISA Advisories·
HIGHVulnerabilities

Vulnerabilities - Qihoo 360 Exposes Wildcard SSL Private Key

Qihoo 360 has leaked its wildcard SSL private key in a public installer. This exposes users to serious security risks, including data interception and impersonation. The company is taking steps to mitigate the fallout.

Cyber Security News·
HIGHVulnerabilities

CISA Issues Security Advisories for Multiple ICS Vulnerabilities

CISA has issued important advisories regarding vulnerabilities in various ICS products. Key systems from Honeywell and Siemens are affected. Users must apply updates to mitigate potential risks. Stay vigilant and secure your infrastructure.

Canadian Cyber Centre Alerts·
HIGHVulnerabilities

Zombie ZIP - New Method Evades Antivirus Detection

A new technique called Zombie ZIP can trick antivirus software during scans. This affects many users relying on antivirus for protection. Stay informed and vigilant to avoid risks.

Malwarebytes Labs·
HIGHVulnerabilities

Red Hat Security Advisory - Critical Linux Kernel Updates

Red Hat has issued a security advisory addressing critical vulnerabilities in the Linux kernel. Multiple products are affected, posing serious risks to users. Immediate updates are necessary to ensure system security and integrity.

Canadian Cyber Centre Alerts·