Companies House suspended its WebFiling service after it emerged that a flaw allowed logged-in users to access other companies’ dashboards, exposing non-public information about directors. The issue affected a service used by around 5 million registered companies.
What happened
- The flaw had been introduced in October 2025, during changes linked to GOV.UK One Login, and went unnoticed for about five months.
- Exposed information included directors’ residential addresses, dates of birth, and email addresses, and users could potentially file changes for other companies.
- WebFiling was taken offline on 13 March and restored on 16 March 2026 after a fix.
- Companies House reported the incident to the ICO and the NCSC, said access was limited to one company at a time, and asked companies to check their records.
Why it mattered
The incident undermined confidence in a register that was being reformed to fight fraud, and exposed home addresses that directors had deliberately kept private.
Lessons for organisations
Access control changes, especially during identity or login integrations, need thorough testing for authorisation flaws. Secure development and change management controls, such as those in ISO/IEC 27001, should include testing that users can only see their own data.
Sources: GOV.UK, Tax Policy Associates
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.