Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Security Flaw in UK Companies House Web Application Exposed

Security Flaw in UK Companies House Web Application Exposed

Posted on March 17, 2026 By CWS

A significant security vulnerability was identified in the web application of Companies House, the UK government agency tasked with maintaining the official register of companies. This flaw potentially exposed the sensitive information of millions of firms.

Discovery of the Vulnerability

The security issue came to light when John Hewitt from Ghost Mail discovered it on March 12. However, the vulnerability had been present for several months before it was finally patched. Hewitt’s findings revealed that logged-in users could access other companies’ accounts on the Companies House platform, risking exposure of sensitive data for five million registered companies.

Details at risk included directors’ personal information such as dates of birth, home addresses, and email addresses. Furthermore, unauthorized changes to a company’s information could have been made, including the submission of falsified filings.

Exploitability and Potential Impact

Exploiting the vulnerability required minimal technical expertise. An attacker could simply choose the ‘file for another company’ option, input the targeted company’s unique number, and use the back button to gain unauthorized access. This ease of exploitation posed a significant threat despite requiring authenticated access.

In response, Companies House confirmed the vulnerability affected the WebFiling service, stating it was introduced in October 2025. The flaw was rectified after the service was temporarily shut down over a weekend.

Company Response and Security Measures

Companies House assured that the vulnerability did not compromise passwords or identity verification data like passports. Moreover, it was not possible for attackers to alter any existing filed documents. The agency believes that data extraction would have been limited to individual company records, viewed singularly by registered users.

While no data breaches or unauthorized changes have been confirmed, Companies House advises companies to review their records and report any discrepancies. The incident underscores the importance of robust cybersecurity measures in protecting sensitive data.

For further information, the UK government has outlined a new Cyber Action Plan, emphasizing the need for enhanced security protocols across all sectors.

Security Week News Tags:Cybersecurity, data exposure, data protection, data security, government agency, online security, security breach, UK Companies House, UK firms, web application vulnerability

Post navigation

Previous Post: LeakNet Ransomware Adopts ClickFix for Attacks
Next Post: Windows 11 Update Resolves Bluetooth Visibility Bug

Related Posts

RMPocalypse: New Attack Breaks AMD Confidential Computing RMPocalypse: New Attack Breaks AMD Confidential Computing Security Week News
Chrome 138 Update Patches Zero-Day Vulnerability Chrome 138 Update Patches Zero-Day Vulnerability Security Week News
Hackers Accessed University of Hawaii Cancer Center Patient Data; They Weren’t Immediately Notified Hackers Accessed University of Hawaii Cancer Center Patient Data; They Weren’t Immediately Notified Security Week News
Portal26 Raises  Million for Gen-AI Adoption Platform Portal26 Raises $9 Million for Gen-AI Adoption Platform Security Week News
SAP Addresses Critical Security Flaws in Latest Patch SAP Addresses Critical Security Flaws in Latest Patch Security Week News
Security Flaw in UK Companies House Web Application Exposed London Hydro Investigates Customer Data Breach Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Homebrew 7.0.0 Unveils Vulnerability Scanner and Enhanced Security
  • Major Breach at Japan’s Digital Agency Exposes 240,000 Records
  • Critical Cisco Email Gateway Flaw Exploited, CISA Warns
  • Underground AI Service ‘Luciferus’ Promoted by Hackers
  • Microsoft’s AI Code of Conduct Prohibits Cyberattacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Homebrew 7.0.0 Unveils Vulnerability Scanner and Enhanced Security
  • Major Breach at Japan’s Digital Agency Exposes 240,000 Records
  • Critical Cisco Email Gateway Flaw Exploited, CISA Warns
  • Underground AI Service ‘Luciferus’ Promoted by Hackers
  • Microsoft’s AI Code of Conduct Prohibits Cyberattacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark