Companies House temporarily shut down its WebFiling service after a security flaw allowed logged-in users to view sensitive data belonging to other companies and potentially submit unauthorized filings on their behalf. The exposed information included directors’ dates of birth, residential addresses, and company email addresses, and the issue raised the possibility that changes to director details or company accounts could have been submitted to another company’s record while the flaw was active. The service was taken offline on 13 March and restored on 16 March after the issue was fixed and independently tested.
Companies House said the flaw affected data not normally published on the public register, but stated that passwords and identity documents such as passports were not exposed. The agency also said the issue was not believed to support large-scale or systematic extraction, with access limited to individual company records viewed one at a time by a registered WebFiling user. Reporting indicates the faulty behavior was introduced by platform changes made in October 2025, and the organization is reviewing whether any company records were altered and plans to contact affected firms if irregular activity is confirmed.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
By 2026-04-03, reporting indicated Companies House was preparing an investment case to modernise legacy systems and strengthen identity checks following the WebFiling incident. Funding and implementation timelines had not yet been finalised.
On 16 March, Companies House publicly disclosed that the flaw may have exposed non-public company data and enabled unauthorized filings, while saying bulk extraction was unlikely. It advised companies to review their registered details and filing history as the investigation continued.
Companies House brought WebFiling back online at 9am on 16 March after remediating the flaw and completing independent testing. The agency said passwords, identity documents, and previously filed documents were not compromised or alterable.
During its response to the WebFiling incident, Companies House notified the Information Commissioner's Office and the National Cyber Security Centre. It also began reviewing whether any unauthorized access or record changes had occurred.
After the issue was publicized by tax professional Dan Neidle on 13 March, Companies House identified the problem and took the WebFiling service offline at 1:30pm that day. The agency began investigating and remediating the bug, which exposed data such as dates of birth, residential addresses, and company email addresses.
The flaw was discovered by John Hewitt of Ghost Mail before it became public. Reports indicate the issue was found in the week before Companies House took action.
Companies House said the WebFiling vulnerability appears to have been introduced during platform changes made in October 2025. The flaw could let an authenticated user with a valid company authentication code access limited non-public details from another company and potentially submit unauthorized filings.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
8 references tracked. Mallory keeps watching after this page renders.
meyka.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourceitpro.com
Open sourcehelpnetsecurity.com
Open sourcehackread.com
Open sourcego.theregister.com
Open sourcegov.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.