Blog
Companies House security issue: What your business should do now
Bethany Hall
Discovered on Thursday 12 March, Companies House suspended its WebFiling system from Friday 13 March until the morning of Monday 16 March. Andy King, Chief Executive of Companies House, has since issued a statement (Update on Companies House WebFiling security issue - GOV.UK) explaining the issues discovered and outlining the steps companies should now take.
The flaw in the Companies House WebFiling service allowed a logged-in user to access the internal dashboard of any of the other five million companies registered on Companies House by entering another company number and simply pressing the back key a few times. Although not accessible to the general public (as you need a Companies House account), Companies House serves over 5 million registered companies, many of whom use the WebFiling service. The statement from the CEO Andy King, suggests that this issue has been present since Companies House updated their WebFiling systems in October 2025, which is a 5 month window.
A company's dashboard contains sensitive, private information about its directors including, their residential addresses, email addresses and dates of birth. Unauthorised access also allows a user to make filings or amend company records. Therefore, modifications could have been made to various company details including its registered address, accounts filings or changes of directors. In his statement, Andy King has now confirmed that unauthorised filings could therefore have been made by an unauthorised individual. Looking at the most serious scenario, UK companies were potentially exposed to company hijacking by bad actors and corporate identity fraud.
As of Monday, 16 March 2026, CEO Andy King reported that Companies House had not yet received any confirmed cases of a company’s data having been accessed or changed without permission. However, investigations are ongoing.
It is very important that companies take the following steps as a matter of urgency:
The period to review is between 1 October 2025 and Friday, 13 March.
The CEO has issued an apology to all registered companies and confirmed that they took immediate action to fix the issue. They have also reported the incident to the Information Commissioner's Office and the National Cyber Security Centre. To ensure all businesses have taken the above precautionary steps, Companies House will be emailing every company’s registered email address to explain how to check their details and what steps to take if they have concerns.
If you have any questions regarding this blog, please contact our Corporate, Commercial & Finance team.
Bethany Hall is a trainee solicitor currently in her fourth seat with the Corporate, Commercial and Finance team.
Roberta Draper advises startup founders, angel investors and established businesses on a variety of corporate and commercial legal matters. She advises on early stage investments, share option schemes, shareholder agreements, share buybacks and company sales and acquisitions.
A serious security vulnerability affecting the five million registered companies on Companies House was recently discovered. More on this below, but we would urge all companies to check their records carefully and ensure there is nothing unexpected in their Companies House filings and dashboard.
At our recent Tech Briefing, 'What tech businesses need to know in 2026', we explored how the EU’s Digital Omnibus package and the UK’s Employment Rights Act will reshape compliance for UK tech SMEs.
Most commercial disputes don’t come from exotic legal issues - they come from everyday contract weaknesses that could have been avoided with a few smart tweaks
2026 is shaping up to be the most consequential year for UK data protection enforcement since the introduction of the EU/UK GDPR regime. With record fines issued in late 2025, a new enforcement playbook on the horizon, and shifting legislative and regulatory expectations, the Information Commissioner’s Office (“ICO”) is signalling a marked transformation in how it supervises, and sanctions, organisations.
Too often, limitation of liability clauses are treated as standard boilerplate - something to tidy up at the end of a negotiation once the “real” commercial points are agreed.
In this article, we share 7 key considerations to help tech founders navigate the journey from seed funding to Series A and beyond.
In November 2025, the European Commission unveiled its Digital Omnibus package – a set of proposals aimed at simplifying (not deregulating) EU rules on data protection, cybersecurity and AI.
In a recent decision on the UK GDPR’s global scope, the Upper Tribunal in The Information Commissioner v Clearview AI Incorporated and Privacy International [2025] UKUT 319 (AAC) confirmed that the UK’s data protection regime can extend well beyond its borders.
Founders and teams across the country are looking for signals that the UK still backs its innovators. Here’s what’s top of the wish-list:
For founders, investors and anyone involved in the tech sector, understanding who owns your software and how to prove it is critical. Whether you’re seeking investment, planning an exit or simply aiming to protect your IP, clarity on ownership can make or break a deal
The Court of Appeal has recently handed down an important decision in respect of data protection law considerations in Farley & Others v Paymaster (trading as Equiniti) [2025] EWCA Civ 1117, providing clarity on the scope of infringement and compensation data protection claims under the UK GDPR and Data Protection Act 2018 (“DPA”). The judgment will be of particular interest to any service provider dealing with and processing large volumes of customer personal data.
At some point in their history, businesses commonly have need for external funding to help their growth trajectory.
In tech, the law often arrives after something has gone wrong. Here are three cautionary tales* and the lessons every founder, CTO and in-house counsel should take away.
The Data (Use and Access) Act 2025 (the “DUAA”), which received Royal Assent on 19 June 2025, introduces targeted reforms to the UK data protection legal framework — particularly the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (“PECR”).
Many of you will know that the Government published, on 23 June, its Modern Industrial Strategy paper and, with it, committed to creating a “predictable, proportionate, and transparent investment screening framework” and launching a 12-week consultation on updating the definitions of the 17 sensitive sectors of the economy as set out in the National Security and Investment Act 2021 (NSIA).
The recent cyberattacks on major UK retailers have put cybersecurity back in the spotlight. But a more significant development for data protection practitioners has been flying under the radar: the Information Commissioner’s Office (ICO) has issued a notable fine directly against a data processor for breaching UK GDPR security obligations - an important shift in enforcement focus.
The 2023/24 tax year marks a major shift in the way unincorporated businesses are taxed. It is a transition year, with HMRC moving from the traditional “current year basis” to a “tax year basis” from 6 April 2024. While this change is intended to simplify the system in the long run, it introduces some short-term complexities (and often tax expense) during the transition year which partners and other sole traders ought to be alive to.
We have a wealth of experience acting for high net worth individuals at the outset of their angel investing journey and for seasoned angel investors who need the occasional bit of legal input.
On 6 April 2025, the first wave of consumer protection provisions under the Digital Markets, Competition and Consumers Act 2024 (“DMCC Act”) came into force, marking the most significant overhaul of UK consumer protection law in over a decade.
In the wake of recent high-profile cyber-attacks on major retailers like Marks & Spencer and Co-op, the UK government has launched a new voluntary Code of Practice for software vendors at its flagship cyber security event, CyberUK 2025. This initiative sets a dynamic baseline for software security and resilience, aiming to help prevent such breaches in the future.
Skip to content Home About Us Insights Services Contact Accessibility
Share insightLinkedIn X Facebook Email to a friend Print