Companies House suspends filing service after glitch puts personal data at risk


Companies House suspended its online filing service after a glitch allowed people to edit the personal data of other businesses and potentially expose them to fraud.

A vulnerability in the UKโ€™s official corporate register allowed people to access other companiesโ€™ details by pressing the back key on their siteโ€™s dashboard.

Data that could reportedly be viewed because of the glitch included directorsโ€™ home addresses, email addresses, and dates of birth.

Companies House was alerted to the issue on Friday by Dan Neidle, founder of Tax Policy Associates.

Mr Neidle said the glitch could be โ€œvery seriousโ€ if it was in place for a long time, adding it was an โ€œabsolutely insane vulnerability in how easy it is to findโ€.

He told the Press Association: โ€œPeople could get enough data about a company and its directors to potentially commit fraud โ€“ to pretend to be it.

โ€œEven worse, they could change the address to their address so they could pick up documents and, if you could file accounts, you could do all kinds of damage.โ€

Discussing the glitch, Mr Neidle added: โ€œIf it was only there for 36 hours, then maybe itโ€™s fine.

โ€œBut if it was there for a month or more, itโ€™s very serious.

โ€œSecurity researchers say 15 days is the average time it takes for a vulnerability to be exploited, and this was a particularly easy vulnerability with no hacking required.โ€

A Companies House spokesperson said on Friday evening: โ€œWe are aware of an issue with our WebFiling service and have closed it while we investigate.

โ€œWe apologise for any inconvenience to our customers.โ€

In guidance for affected customers, Companies House stated: โ€œIf you miss your filing deadline due to the service being unavailable, thereโ€™s no need to call us.

โ€œFile as soon as you can once the service is available, and take a screenshot of any error messages and note the time and date. Weโ€™ll take this evidence into account if you cannot file.โ€

Under the Computer Misuse Act 1990, unauthorised access to computer material carries a maximum prison sentence of two years, and the penalty increases to up to five years for accessing data with the intent to commit further offences, such as fraud.

Companies House maintains records of more than five million companies, including large FTSE 100 companies such as AstraZeneca, Shell, and Tesco.

Leave comment

Your email address will not be published. Required fields are marked with *.