Companies House online filing returned to normal after issue allowing users to change director details


  • Companies House closes WebFiling after misconfiguration
  • Logged in users can view or edit other companies’ data
  • Sensitive details such as dates of birth and addresses briefly exposed, now fixed

Companies House, the UK’s official business registration office, was leaking sensitive company data to unauthorized third parties. The discovery of the vulnerability forced it to shut down one of its services over the weekend while it investigated and fixed the problem.

In a press release issued earlier this morning, Companies House CEO Andy King said the organization spotted a misconfiguration on Friday afternoon, “which meant that a user logged into our WebFiling service could potentially access and modify certain elements of another company’s information without their consent after completing a specific set of actions.”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top