Skip to content
>_ITDITDWeb Security Platform

Security Guides

Not a hack from outside, but logged-in users seeing other companies — the Companies House WebFiling flaw and what directors and developers should do

UK Companies House took WebFiling offline from March 13 to 16, 2026, after a defect introduced in an October 2025 update let logged-in users potentially view other companies' directors' birth dates and home addresses, or make filings. What directors should check, and the lesson for developers.

Published 2026-09-30 Updated 2026-09-30 Last verified 2026-09-30 14 min read

For: directors and company secretaries of UK-registered companies (including UK subsidiaries of overseas groups), accountants and agents who file on their behalf, and developers who build services where many customers share one system. This article is based on statements, guidance and the all-company email that Companies House published on GOV.UK, and the letter its Chief Executive sent to a House of Commons committee. It does not describe how to reproduce or exploit the defect.

What directors and company staff should do today

1

Check your registered details and filing history

Companies House asks every company to check its registered details and filing history as a precaution, in WebFiling and on the public Find and update company information service. Look for director appointments or terminations, registered office changes or accounts that you did not file. According to Companies House, existing documents could not be removed or altered, and any accepted filing appears in the filing history.

2

If something looks wrong, report it the way Companies House asks

Email enquiries@companieshouse.gov.uk with "WebFiling issue" in the subject line, including your company name and number and as much detail about the concern as you can. Companies House says the more information you give, the easier it is to investigate and resolve.

3

Turn on the free Follow service

Companies House recommends Follow: open your company's page on Find and update company information and select "Follow this company" to get an instant email whenever a document is filed. Follow does not alert you to changes in information that is not published on the public register; to see your company's private information, log in to WebFiling.

4

Review your company authentication code

The company authentication code is a 6-character alphanumeric code that authorises online filings and is the equivalent of a company officer's signature. Companies House guidance says to treat it with the same care as a bank card PIN, and to change it if someone you do not trust knows it, or if someone no longer authorised to file, such as former staff or a previous accountant, knows it. Companies House will never ask for the code over the phone. Note that for this incident Companies House said passwords do not need resetting and did not ask companies to change codes; this is general housekeeping.

5

Recognise the genuine notification email

Companies House emailed every company's registered email address between March 17 and 19 from companies.house@notifications.service.gov.uk, a no-reply address. If an email claiming to be about this incident arrives, do not log in from its links; open WebFiling on GOV.UK yourself (see What is phishing?).

6

If the closure made you miss a deadline, keep evidence and appeal

If you missed an accounts filing deadline because WebFiling was closed from March 13 to 16, Companies House says you do not need to call; file as soon as possible and keep a record of when you tried to access the service. If a late filing penalty is applied, appeal online and include screenshots and timestamps.

User A logs in and requests Company B's details

↓

① Authentication: who is this?

A logged-in registered user → passes (this worked)

② Authorization: may they handle B?

On a specific sequence of actions, this check did not hold

↓

Possibly visible

Day of birth, residential address, company registered email

Possibly filed

New filings (accounts, director changes); existing documents could not be altered

Defence: run ② on every request, and test on every release that asking for another company is refused

The issue was not the login check but the next check: may this user handle this company? (A general explanation of the concept, not Companies House's actual implementation or a way to reproduce it.)

What happened (from Companies House)

Everything below is as stated in the Companies House statement (March 16, updated March 18), the guidance page "WebFiling issue: information and updates" (published March 20, updated April 8), the copy of its email to all companies (March 17), and its Chief Executive's letter to the Commons Business and Trade Committee (dated March 19, published March 25).

  1. October 11, 2025

    A major system update to WebFiling. According to Companies House, the defect was introduced then.
  2. Fri March 13, 2026

    Companies House became aware of the issue following an email from a third party. It closed WebFiling at 1:30pm to investigate and fix it.
  3. Mon March 16, 9am

    WebFiling reopened after independent, comprehensive testing. A statement was published the same day; Companies House said it had reported the incident to the Information Commissioner's Office (ICO) and the National Cyber Security Centre (NCSC).
  4. March 17–19

    Emails sent to every company's registered email address.
  5. March 19

    In a letter to the Commons committee, the Chief Executive said monitoring was designed to detect system failures and cyber-attacks, and was not triggered because this was a functional defect.
  6. March 20

    Guidance page "WebFiling issue: information and updates" published.
  7. April 8

    Guidance updated: a very small number of instances of unauthorised access or attempted changes identified, believed to be linked, with no evidence of wider exploitation. Companies House said it would engage an independent third party to review its approach, and would not update the page further until any potential investigations, including by the ICO, are concluded.
Oct 2025–
Period the defect existed (October 11, 2025 to March 13, 2026)
Mar 13–16
WebFiling closed (1:30pm on the 13th to 9am on the 16th)
3 kinds
Non-public data possibly visible: day of birth, home address, registered email
Not affected
Passwords, identity verification data, existing filed documents (per Companies House)
What was affected, and what was not (per Companies House)
Possibly visible
For directors and PSCs, the day of the date of birth (usually only month and year are on the public register) and residential address; the company registered email address
Possibly possible
Unauthorised filings (for example new accounts or changes of director). Existing documents could not be edited or removed, and accepted filings appear in the filing history
Who could use it
Only a logged-in registered user (such as a company officer or agent) carrying out a specific sequence of actions; not the general public. Companies House says it could not be used to extract data in bulk
Not affected
Passwords (no reset needed); identity verification data such as passport information and personal codes; existing filed documents; people who had applied to protect their details under the Companies Act 2006
Cause (per Companies House)
An application defect introduced with a major release. The Chief Executive's letter says indicative findings suggest it was not identified during testing or by peer review
Traceability
According to the letter, all changes are recorded and linked to the logged-in account, so it is possible to trace who changed a record; it was not currently possible to determine how many times information was accessed through the defect
Reports and next steps
Reported to the ICO and NCSC. A detailed lessons-learned review, followed by an independent third-party review

How to read the figures: the very small number has not been published

Companies House's April 8 update refers to "a very small number" of instances of unauthorised access or attempted changes but gives no count. This article does not use counts of incidents or of companies viewed that have not been officially published. It also does not describe the sequence of actions that triggered the defect, since that could enable misuse.

What directors should know: why birth dates and home addresses matter

In the UK, directors' residential addresses and the day of their date of birth are normally kept off the public register. This time they may have been visible to other logged-in users. For a UK subsidiary of an overseas group whose director lives abroad, that overseas home address may be among the data involved.

Public: anyone can see on the register

  • Director names, month and year of birth
  • Correspondence (service) address
  • Filing history (accounts, director changes and so on)

Non-public: possibly visible in this incident

  • Day of birth (with month and year, the full date)
  • Residential addresses of directors and PSCs
  • Company registered email address (not published)

A full date of birth plus a home address is a combination often used to answer identity-check questions. The company registered email address is where official Companies House messages go. The defences: never treat someone knowing your birth date or address as a reason to trust a call or email, and for any message claiming to be from Companies House at the registered email address, open GOV.UK yourself instead of using its links.

The lesson for developers: attack monitoring won't find authorization bugs

This was not an intrusion from outside. It was a legitimate, logged-in user being able to see another company's (another tenant's) data. In security terms it is a broken access control problem, close to the type known as IDOR (insecure direct object reference). The difference between authentication and authorization is covered in Authentication vs authorization.

This site's view: stop it with authorization tests, not attack monitoring

In a letter to the Commons committee, the Companies House Chief Executive explained that its monitoring was designed to detect system failures and cyber-attacks, and was not triggered because this was a functional defect. The issue came to light through an email from a third party. There is a lesson here for anyone building a service where many customers share one system. Access through an authorization gap looks like a legitimate, logged-in user doing ordinary things: no suspicious traffic, no mass downloads. So it is more reliable to stop it when you build than to watch for it afterwards.

1. Check "may this user handle this company?" on every request. Do not rely on the fact that an earlier screen or step already checked. For every read and write, verify on the server the relationship between the logged-in user and the target record.
2. Automate "requesting someone else's data is refused" tests, and run them on every release. Act as user A, request to view or change company B's data, and assert that it is refused. According to Companies House, this defect came in with a major release and was not caught by testing or peer review. Functional tests check that things that should work do work; authorization tests check that things that must not work don't. The latter are easiest to lose in big releases, so automate them rather than relying on manual checks.
3. Log changes against the account that made them. Companies House says every change was recorded and linked to the logged-in account, so it can trace who made a change, while it could not yet tell how many times data was viewed. Logging reads as well lets you show the scope of an incident afterwards.
4. Give outsiders a way to report. This issue was found through an email from outside. A published reporting contact (for example, a security.txt file) helps people who find a problem tell you quickly.

For another European case this year in which itineraries leaked from a customer list, see the Trenitalia data breach; for one in which a government application portal's user list leaked, see the France Titres (ANTS) breach.

Sources (public record)

The facts in this article come from the public sources below. Speculation in media coverage, reproduction details and unpublished counts are not used.

  • Companies House, "Update on Companies House WebFiling security issue" (March 16, 2026; updated March 18) — gov.uk
  • Companies House, "WebFiling issue: information and updates" (published March 20, 2026; updated April 8) — gov.uk
  • Companies House, "Email to registered companies about the WebFiling security issue" (March 17, 2026) — gov.uk
  • House of Commons Business and Trade Committee, "Letter from Companies House relating to online filing service faults, 19 March 2026" (published March 25, 2026) — committees.parliament.uk
  • Companies House, "Company authentication codes for online filing" — gov.uk
  • Companies House, "Protecting your company from fraud and scams" — gov.uk

Update history

2026-09-30: First version, based on the Companies House statement (March 16, updated March 18), its guidance page (April 8 version), the copy of its all-company email, the letter to the Commons committee (dated March 19), and its guidance on authentication codes and fraud. Companies House has said it will not update its guidance page until any potential investigations, including by the ICO, are concluded; this article will be updated if findings or the independent review are published.

FAQ

QWhat data may have been exposed by the Companies House WebFiling issue?
A

According to Companies House, data not normally published on the public register may have been visible to other logged-in registered users: the day of the date of birth for directors and people with significant control (PSCs) (usually only the month and year are public), residential addresses for directors and PSCs, and the company registered email address.

QCould someone have changed my company's records?
A

Companies House says it was technically possible to file updates without consent, for example new accounts or changes of director. Existing filed documents could not be altered or removed, and any accepted filing would appear in the filing history on the public register. It asks all companies to check their registered details and filing history as a precaution.

QWere passwords or identity verification data exposed?
A

Companies House says you do not need to reset your WebFiling password, and that no identity verification data, such as passport information or personal codes, was accessed. People who had applied to protect their personal details under the Companies Act 2006 were not affected by this issue.

QWas this a hack or cyber-attack?
A

Companies House says it was not the result of any malicious attempt to breach its systems from outside and not a cyber-attack, but a defect introduced when it updated WebFiling on October 11, 2025. The defect could only have been exploited by an authenticated user (such as a company officer or agent) carrying out a specific sequence of actions, between October 11, 2025 and March 13, 2026.

QWas the flaw actually exploited?
A

In its April 8, 2026 update, Companies House said its investigations had identified a very small number of instances of unauthorised access or attempted changes, which it believes are linked; it has no evidence of wider exploitation and believes the issue was not used to extract data in large volumes. It has not published a number.

QWhat should company directors do?
A

Companies House asks companies to check their registered details and filing history in WebFiling and on the Find and update company information service. If anything looks wrong, email enquiries@companieshouse.gov.uk with 'WebFiling issue' in the subject line, including the company name and number. It also recommends the free Follow service, which emails you whenever a document is filed for your company.