A critical security flaw at Companies House, the UK’s official government registry for limited companies, has raised alarms after potentially exposing sensitive information of millions of businesses. Companies are now being urged to urgently review their registered details following this unprecedented breach that allowed unauthorized viewing and editing of company data.
What Happened: The Companies House Data Glitch Uncovered
The troubling vulnerability emerged after a software update to Companies House’s WebFiling system—the online platform where company directors submit essential legal documents such as annual accounts and confirmation statements. Introduced in October 2025, this update inadvertently created a loophole enabling logged-in users to access and even modify details belonging to other companies without authorization.
The flaw came to light on Thursday, when John Hewitt, a corporate services provider from Ghost Mail, discovered the issue while navigating his own company’s dashboard. By pressing the back button multiple times, he unexpectedly gained access to another company’s dashboard, revealing confidential director information like home addresses and email contacts.
Upon being alerted by Hewitt and the independent think tank Tax Policy Associates, Companies House swiftly shut down the WebFiling service on Friday to investigate and resolve the problem. The agency confirmed it restored full service by Monday and emphasized that no passwords or identity verification documents—such as passports—were compromised during the incident.

Scope of the Breach and Ongoing Investigation
Companies House’s investigation revealed that sensitive data including dates of birth and residential addresses may have been accessible to unauthorized users. Moreover, there was a potential risk that fraudulent filings—such as unauthorized changes to company directors or submission of false accounts—could have been made on behalf of other companies.
Despite these risks, the agency assured that no previously filed documents, including accounts and confirmation statements, were altered during the breach. The incident has been reported to both the Information Commissioner’s Office (ICO) and the National Cyber Security Centre (NCSC), with ongoing inquiries into whether any data was actually accessed or changed unlawfully.
Andy King, Chief Executive of Companies House, issued a formal apology, stating, “We take our responsibility to protect the data entrusted to us extremely seriously.” King highlighted the swift actions taken to rectify the issue and pledged full support to any affected companies to maintain the trust placed in their services.
What Companies Need to Do Now
The ICO has confirmed receipt of Companies House’s report and is advising all UK businesses to proactively verify their registered company details. Companies will receive official emails at their registered addresses outlining how to check for unauthorized changes and what steps to take if they suspect their information has been compromised.
Business owners are encouraged to regularly monitor their records on Companies House and promptly report any suspicious activity. Complaints should include detailed evidence to assist investigators in tracing potential misuse. This vigilance is critical to preventing further exploitation and safeguarding company data integrity.

Why This Matters: Implications for UK Businesses and Data Security
This incident underscores the importance of robust cybersecurity measures within government agencies managing sensitive corporate data. Companies House plays a pivotal role in the UK’s business ecosystem, facilitating transparency and legal compliance for millions of firms.
The exposure of personal contact details and potential unauthorized filings not only threatens individual businesses’ privacy but could also enable fraud, identity theft, and other malicious activities. For SMEs and large corporations alike, maintaining confidence in official registries is essential for smooth operations, investor assurance, and regulatory adherence.
Furthermore, this breach highlights the ongoing challenges governments face in securing digital platforms amid increasing cyber threats. It serves as a cautionary tale for other public sector services undergoing digital transformation to rigorously test new systems before deployment.
Looking Ahead: Restoring Trust and Strengthening Protections
Companies House’s commitment to transparency and swift resolution is a positive step toward rebuilding trust. However, continuous monitoring, enhanced security protocols, and clear communication with stakeholders will be vital moving forward.
UK businesses should view this event as a prompt to review their own cybersecurity practices, ensuring that they promptly detect and respond to any irregularities in their company data.
While the full impact of the breach remains under investigation, this episode reinforces the critical need for vigilance, both from government agencies and the business community, in protecting sensitive corporate information in an increasingly digital world.









