Companies House filing flaw leaves directors to check their own records
A WebFiling bug could let logged-in users view and change other companies’ details for five months. Companies House says no misuse is confirmed, but the government cannot yet say how many accounts were affected

- The flaw was found by a corporate services provider and reported to Companies House through Tax Policy Associates.
- Tax Policy Associates found that a test change’s confirmation email went to the person filing, so a targeted company may never have been warned.
- Directors should check filing history back to October 2025, sign up to the free Follow alerts and treat follow-up emails about the incident with suspicion.
Between 17 and 19 March, Companies House emailed every company’s registered email address to ask directors to check their details and filing history, and on 18 March it updated its statement on the WebFiling security issue. The flaw had been open for five months, and in written answers to MPs published on 19 March the Department for Business and Trade said “it is not currently possible to determine the number of unique user accounts affected.”
WebFiling is the online service many small companies use to file accounts and update their details. From a system update on 11 October 2025, a logged-in user could open another company’s private dashboard, see information that is not on the public register and file changes in that company’s name. Companies House switched the service off at 1.30pm on Friday 13 March, once it had learned of the fault, and had it back by 9am on Monday 16 March after independent testing.
The bug is fixed. The harder question for the directors of the UK’s small companies is whether anyone used it in the five months it was open – and how they would know if someone had.
What was exposed
According to Companies House’s statement, a logged-in WebFiling user could have seen the day of birth and residential address of directors and people with significant control (PSCs), and the company’s registered email address. None of these appears on the public register. The same user could also have filed updates without consent, such as new accounts or a change of director.
Companies House says passwords were not compromised, no identity verification data such as passport information was accessed and no documents already on file could have been altered. Directors who had applied to protect their personal details under the Companies Act 2006 were not affected. It believes the issue could not have been used to extract data in large volumes, because any access was limited to individual records viewed one at a time.
The register is large. Companies House counted 5,450,364 companies on it at the end of December 2025, of which 4,876,981 were on what it calls the effective register.
Two accounts of the same flaw
As first reported by Dan Neidle of Tax Policy Associates, the flaw was discovered on 12 March by John Hewitt of Ghost Mail, a corporate services provider. According to Tax Policy Associates, Hewitt could not get a response from Companies House, so he contacted Neidle, who tested the flaw with a consenting company’s permission and then alerted Companies House. The service went offline soon after, and Tax Policy Associates published only once it had.
Its account makes clear how little skill the exploit needed: no technical hacking, only a short sequence of ordinary browser steps by a logged-in user. Tax Policy Associates notes that anyone could obtain a login by incorporating a company for £100. It also found that when a test change was made, the confirmation email went to the person making the change rather than to the company concerned.
That detail matters for small firms. A director who relies on Companies House emails to flag unexpected filings may not have been told about a change made this way.
Companies House’s email to companies says the issue “was not the result of a malicious attempt to attack our systems. It is not a cyber-attack.” It has reported the incident to the Information Commissioner’s Office (ICO) and the National Cyber Security Centre (NCSC). In its statement it said it had no reports at that stage of data being accessed or changed without permission, while stressing that its investigation was continuing.
Andy King, chief executive of Companies House, apologized. “I recognise that this incident will have caused concern and inconvenience to many of the companies and individuals who rely on our services,” he wrote.
The written answers, given by Blair McDougall for the Department for Business and Trade, add some detail. He said Companies House notified the ICO on 13 March and that the service was retested by government-approved testers, including external specialists. He said investigations had found no subsequent confirmed cases of personal data being accessed without permission and no confirmed evidence of records being changed.
Tax Policy Associates takes a less settled view. It argues that calling the flaw a “specific set of actions” undersells how easy it was to use, and that the key unanswered question is whether Companies House’s logs can show which accounts opened other companies’ dashboards. Companies House says it is analyzing its data to identify anomalies and will take firm action if it finds evidence of misuse.
Why small companies carry the risk
The exposed fields matter. Tax Policy Associates says the data is of the kind used for impersonation, phishing and identity checks, and that directors of small companies are the likelier targets, because larger firms usually stop one person from authorizing payments alone. The security specialists it consulted thought a criminal group would use such a flaw selectively rather than scrape the whole register. That remains a hypothesis: no misuse had been confirmed when the written answers were published.
There is also a second-order risk. A mass email from Companies House about a security incident, sent to every company in the UK, is a ready-made template for phishing. Any message that claims to follow up on the WebFiling issue and asks for a login, an authentication code or a payment deserves suspicion. Companies House says its genuine emails came from its notifications.service.gov.uk address.
What to do now
Every company, whether or not it files online, should check its registered details and filing history in WebFiling and on the Find and update company information service, looking for changes of registered office, director or PSC and any accounts it did not file between October 2025 and March 2026. Anything unexpected should go to Companies House by email with ‘WebFiling issue’ in the subject line and as much supporting detail as possible.
Directors should also sign up to Companies House’s free Follow service, which sends an email alert whenever a document is filed for a chosen company, including their own. Given what Tax Policy Associates found about confirmation emails, that alert is worth more than the confirmation a filer receives. Accountants and company secretarial agents who received the email on behalf of clients have been asked to forward it to every director they act for.
Firms that use Companies House data to check new suppliers or customers should apply extra scrutiny to recent changes of director or registered office before paying into a new bank account. The register is only as reliable as the controls around it, and for five months those controls had a hole in them. Until Companies House can say who used it, the burden of spotting a bad filing sits with each company.
Get The VETTDD BriefingThe week in the technology channel, every week.
Subscribe freeSources
- Companies House, “Update on Companies House WebFiling security issue”, news story, 16 March 2026, updated 18 March 2026. https://www.gov.uk/government/news/update-on-companies-house-webfiling-security-issue
- Companies House, “Email to registered companies about the WebFiling security issue”, correspondence, 17 March 2026. https://www.gov.uk/government/publications/email-to-registered-companies-about-the-webfiling-security-issue/email-to-registered-companies-about-the-webfiling-security-issue
- Tax Policy Associates, “Companies House flaw exposed five million directors and enabled company hijacking”, Dan Neidle, 13 March 2026, updated 17 March 2026. https://taxpolicy.org.uk/2026/03/13/companies-house-security-vulnerability-directors-addresses/
- UK Parliament, written question UIN 121098 (unique user accounts), answered by Blair McDougall, 19 March 2026. https://questions-statements.parliament.uk/written-questions/detail/2026-03-16/121098
- UK Parliament, written question UIN 121103 (ICO notification), answered by Blair McDougall, 19 March 2026. https://questions-statements.parliament.uk/written-questions/detail/2026-03-16/121103
- UK Parliament, written question UIN 120980 (security testing), answered by Blair McDougall, 19 March 2026. https://questions-statements.parliament.uk/written-questions/detail/2026-03-16/120980
- UK Parliament, written question UIN 121097 (date the flaw was introduced), answered by Blair McDougall, 19 March 2026. https://questions-statements.parliament.uk/written-questions/detail/2026-03-16/121097
- UK Parliament, written question UIN 120979 (unauthorized changes), answered by Blair McDougall, 19 March 2026. https://questions-statements.parliament.uk/written-questions/detail/2026-03-16/120979
- Companies House, “Incorporated companies in the UK October to December 2025”, official statistics, 29 January 2026. https://www.gov.uk/government/statistics/incorporated-companies-in-the-uk-october-to-december-2025/incorporated-companies-in-the-uk-october-to-december-2025




