Corporate Registry Rocked by Six-Month Data Exposure
March 20, 2026, 3:44 am

Location: United Kingdom, England, Wilmslow
Employees: 201-500
Founded date: 1984

Location: United Kingdom
Employees: 1001-5000
Founded date: 1954
Total raised: $5.97B
National Cyber Security Centre (NCSC)
Location: United Kingdom, England, London
Employees: 201-500
Founded date: 2016
Companies House WebFiling service faced a major security breach. A flaw, live for six months, exposed sensitive director data. Users could view personal details like dates of birth and addresses. Potential for fraudulent record changes existed. The service closed temporarily, then reopened. Companies House informed the ICO and NCSC. Passwords were not compromised. The incident raises significant concerns about corporate data integrity. It questions the reliability of public business records. Users are urged to check their information. Companies House vows strong action against any exploiters. This breach underscores the constant threat to digital corporate security.
A major security vulnerability hit Companies House. Their WebFiling service suffered a significant flaw. Personal data of listed directors was exposed. This breach sent shockwaves through the UK business community.
The system glitch was severe. It allowed unauthorized users access. They could view sensitive information. This included dates of birth, residential addresses, and company email addresses. The risk extended beyond viewing. Unauthorized filings were a real possibility. Changes to accounts or director details could have occurred.
Companies House moved swiftly. They closed the WebFiling service. The closure happened on March 13. This followed the discovery of the flaw. An immediate investigation began. They reopened the service on March 16. Extensive testing confirmed the issue was resolved.
The vulnerability was not new. It had been active for an alarming six months. A system update in October 2025 introduced the flaw. This extended duration raised serious questions. It highlighted a critical oversight in system integrity checks.
User data protection is paramount. Companies House emphasized key limitations. Access was restricted to existing users. These users already held authorized codes. They possessed valid login details. Passwords remained secure. Identity verification data, like passport details, was safe. No existing filed documents could be altered. This included accounts and confirmation statements.
The registry conducted a thorough investigation. They found no evidence of mass data extraction. Any changes would have required individual action. This offered some reassurance. However, the potential for targeted abuse remained.
Concerns mounted rapidly. The integrity of corporate records was at stake. Public trust in business data relies on accuracy. This incident eroded that trust. The assumption of record sanctity faced a direct challenge.
Companies House took immediate regulatory steps. They notified the Information Commissioner’s Office (ICO). The National Cyber Security Centre (NCSC) also received a report. These actions are standard protocol. They reflect the seriousness of the incident.
The registry is actively reviewing data. They seek any anomalies. Users will receive guidance. This includes instructions on checking their records. The message is clear: vigilance is essential.
Companies House issued an apology. They acknowledged the concern. They recognized the inconvenience caused. The organization stressed its commitment to data protection. Swift action was taken. Service restoration was a priority. Support for affected parties is ongoing. They aim to regain public trust.
Legal ramifications loom for exploiters. Companies House warned of firm action. Unauthorized access or data alteration will not be tolerated. Severe penalties await those who exploited the flaw. This underscores the legal gravity of such cyber intrusions.
The incident serves as a stark reminder. Digital security is a constant battle. Even established government registries face threats. Robust systems are not enough. Continuous monitoring and rapid response are vital. Regular security audits are non-negotiable.
Businesses must learn from this breach. Data protection strategies require constant review. Employee training on security best practices is crucial. Strong internal controls must complement external safeguards. The digital landscape demands perpetual readiness.
This event transcends national borders. It highlights universal challenges in cybersecurity. Public records must remain uncompromised. The integrity of business information underpins economic stability. Trust in digital systems is foundational. When that trust falters, widespread impact follows.
Companies House acted, but the damage was done. Six months of vulnerability is a long time. The ripple effect will be felt. Businesses must strengthen their defenses. Governments must enhance their digital fortresses. The future of data security depends on it. Constant vigilance is the only path forward.
A major security vulnerability hit Companies House. Their WebFiling service suffered a significant flaw. Personal data of listed directors was exposed. This breach sent shockwaves through the UK business community.
The system glitch was severe. It allowed unauthorized users access. They could view sensitive information. This included dates of birth, residential addresses, and company email addresses. The risk extended beyond viewing. Unauthorized filings were a real possibility. Changes to accounts or director details could have occurred.
Companies House moved swiftly. They closed the WebFiling service. The closure happened on March 13. This followed the discovery of the flaw. An immediate investigation began. They reopened the service on March 16. Extensive testing confirmed the issue was resolved.
The vulnerability was not new. It had been active for an alarming six months. A system update in October 2025 introduced the flaw. This extended duration raised serious questions. It highlighted a critical oversight in system integrity checks.
User data protection is paramount. Companies House emphasized key limitations. Access was restricted to existing users. These users already held authorized codes. They possessed valid login details. Passwords remained secure. Identity verification data, like passport details, was safe. No existing filed documents could be altered. This included accounts and confirmation statements.
The registry conducted a thorough investigation. They found no evidence of mass data extraction. Any changes would have required individual action. This offered some reassurance. However, the potential for targeted abuse remained.
Concerns mounted rapidly. The integrity of corporate records was at stake. Public trust in business data relies on accuracy. This incident eroded that trust. The assumption of record sanctity faced a direct challenge.
Companies House took immediate regulatory steps. They notified the Information Commissioner’s Office (ICO). The National Cyber Security Centre (NCSC) also received a report. These actions are standard protocol. They reflect the seriousness of the incident.
The registry is actively reviewing data. They seek any anomalies. Users will receive guidance. This includes instructions on checking their records. The message is clear: vigilance is essential.
Companies House issued an apology. They acknowledged the concern. They recognized the inconvenience caused. The organization stressed its commitment to data protection. Swift action was taken. Service restoration was a priority. Support for affected parties is ongoing. They aim to regain public trust.
Legal ramifications loom for exploiters. Companies House warned of firm action. Unauthorized access or data alteration will not be tolerated. Severe penalties await those who exploited the flaw. This underscores the legal gravity of such cyber intrusions.
The incident serves as a stark reminder. Digital security is a constant battle. Even established government registries face threats. Robust systems are not enough. Continuous monitoring and rapid response are vital. Regular security audits are non-negotiable.
Businesses must learn from this breach. Data protection strategies require constant review. Employee training on security best practices is crucial. Strong internal controls must complement external safeguards. The digital landscape demands perpetual readiness.
This event transcends national borders. It highlights universal challenges in cybersecurity. Public records must remain uncompromised. The integrity of business information underpins economic stability. Trust in digital systems is foundational. When that trust falters, widespread impact follows.
Companies House acted, but the damage was done. Six months of vulnerability is a long time. The ripple effect will be felt. Businesses must strengthen their defenses. Governments must enhance their digital fortresses. The future of data security depends on it. Constant vigilance is the only path forward.