What Happened: The Companies House Security Flaw Explained

In August 2026, a significant security vulnerability in the Companies House online filing system was identified, potentially affecting the accounts of approximately 5 million UK business owners. The bug created a pathway for unauthorised access to business records and filing systems, exposing firms to potential account hijacking, fraudulent filings, and reputational damage.

The vulnerability was discovered in the authentication mechanism that verifies user identity when accessing the Companies House WebFiling service—the primary platform used by founders, company secretaries, and accountants to file annual accounts, changes to company details, and statutory documents with the UK's official business registry.

Companies House, the executive agency responsible for incorporating and dissolving limited companies in the UK, confirmed the issue affected users who had not updated their account security credentials recently. The flaw allowed attackers to potentially bypass standard password protections under specific conditions, gaining access to sensitive company information and filing capabilities.

The Scale of the Risk: Who Was Affected

The vulnerability had the potential to impact a significant proportion of the UK's active business population. According to the latest Companies House statistics, there are approximately 3.9 million active limited companies on the register. However, the broader exposure included:

  • Limited companies: Entities required to file annual accounts and confirmation statements
  • Sole traders and partnerships: Those with Companies House accounts for filing purposes
  • Professional advisors: Accountants, company secretaries, and corporate compliance agents managing multiple client accounts
  • Investors and shareholders: Individuals with authorised access to company records

The 5 million figure likely represents the total number of individual user accounts registered with Companies House's online services, rather than the number of companies affected. This means a single security breach could compromise access to thousands of business filings simultaneously.

For startup founders and early-stage operators, the implications were particularly severe. Early-stage companies often have limited administrative overhead and may not monitor account access logs regularly. A compromised account could allow an attacker to:

  • File false annual accounts or confirmation statements
  • Change registered office addresses or director details
  • Fraudulently dissolve the company
  • Alter shareholding structures without consent
  • Access confidential financial information and shareholder details

Regulatory and Compliance Implications for UK Founders

The vulnerability raised urgent questions about compliance obligations and liability under UK law. Directors and company secretaries have a legal duty under the Companies Act 2006 to ensure the accuracy of information filed at Companies House. If a fraudulent filing occurs due to account compromise, the responsibility remains with the registered officer, regardless of whether the filing was authorised.

This created a challenging situation for affected business owners:

Duty of care and due diligence: Directors must take reasonable steps to protect their Companies House accounts. Under Companies House guidance on online filing security, users are advised to use strong passwords, enable two-factor authentication, and regularly review account activity. However, if the vulnerability was exploited before a user became aware of it, establishing negligence becomes complex.

Notification and disclosure: Under GDPR and the Data Protection Act 2018, if personal data (including company financial information and director details) was compromised, affected individuals must be notified within 72 hours of discovery. Companies House faced pressure to communicate transparently with all potentially affected users.

Insurance and indemnity: Directors' and officers' liability insurance (D&O insurance) may provide cover for costs arising from fraudulent filings, but only if the policy explicitly includes cyber-related breaches. Many early-stage founders do not carry this insurance, leaving them personally liable for costs of restoring accurate company records.

How the Vulnerability Potentially Worked

While Companies House did not disclose full technical details (standard practice to prevent copycat attacks), security experts identified the flaw as likely stemming from one of several common authentication weaknesses:

Session hijacking: Attackers could potentially steal or replay session tokens—the digital credentials that prove you're logged in. If session tokens were not properly invalidated after logout or timeout, an attacker could use an old token to access an account without entering the correct password.

Insufficient multi-factor authentication: Although Companies House recommended two-factor authentication, it may not have been enforced for all users or certain account types. Attackers using compromised username-password combinations could access accounts protected only by single-factor authentication.

API vulnerabilities: The Companies House filing system includes APIs (application programming interfaces) that third-party software uses to submit filings. If these APIs had weak authentication checks, attackers could submit unauthorised requests directly without logging into the web interface.

Social engineering combined with weak account recovery: Attackers could use publicly available company information (director names, addresses, company details visible on the Companies House register) to attempt account password resets. If the security questions or recovery processes relied on information readily available in public records, this attack vector became viable.

Immediate Actions: What Founders Should Do Now

If your business has an account with Companies House, the following steps are essential to protect your company:

  1. Change your password immediately: Log in to Companies House WebFiling and reset your password to a unique, strong credential (minimum 16 characters, mix of upper and lowercase letters, numbers, and symbols). Avoid reusing passwords from other services.
  2. Enable two-factor authentication: Access your account settings and activate 2FA using an authenticator app (not SMS, which is more vulnerable to interception). This adds a second layer of security even if your password is compromised.
  3. Review recent account activity: Check your Companies House account login history and filing records for the past 6–12 months. Look for unfamiliar logins from unusual locations or IP addresses. If Companies House provides activity logs, download and archive them for records.
  4. Monitor your company's public record: Visit the Companies House public register weekly for the next three months and check for unauthorised changes to your registered office, directors, shareholders, or filed documents. Set up a Google Alert for your company name to receive notifications of changes.
  5. Notify your accountant and company secretary: If you use external advisors, inform them immediately so they can take similar precautions on their systems. If they manage multiple client accounts through a single login, this is particularly critical.
  6. Consider a protective filing: If you suspect your account has been compromised, file a correction or dispute with Companies House to establish a formal record that any fraudulent filings were not authorised by you.
  7. Check your personal credit:**Report any suspicious activity to Experian, Equifax, and CallCredit. Fraudulent company filings are sometimes used to support identity theft or fraudulent business loans.

Companies House's Response and System Improvements

Companies House acted relatively quickly to patch the vulnerability once identified. The agency's response included:

System patching: The technical flaw was remediated, and all affected systems were secured within a defined timeframe. The specific patch details were not released publicly to prevent attackers from targeting unpatched legacy systems.

Mandatory password reset notices: Companies House issued communications to affected users recommending immediate password changes. However, the scale of the vulnerability meant that not all users received notifications simultaneously, creating a lag period during which accounts remained at risk.

Enhanced monitoring: Post-incident, Companies House implemented additional logging and anomaly detection to identify suspicious filing activities—such as multiple filings from the same account in rapid succession or filings from geographical locations inconsistent with the registered user's profile.

Public guidance updates: The incident prompted Companies House to update its cybersecurity guidance. The agency now more explicitly recommends two-factor authentication as a standard practice rather than an optional enhancement.

Broader Lessons: Why This Matters Beyond Companies House

This vulnerability highlights systemic risks in critical UK business infrastructure. Companies House is not merely a filing cabinet—it's the foundational registry upon which corporate identity, credit, and transactions depend. Compromising it has cascading effects across the entire business ecosystem.

Third-party integrations create risk: Accountants, payroll providers, and compliance software integrate with Companies House to automate filings. A vulnerability in Companies House authentication can be exploited through these third-party tools, affecting entire networks of businesses using the same software provider.

Regulatory and financial consequences: A fraudulent annual accounts filing can lead to:

  • Loan applications rejected or recalled
  • Supply chain disruptions if creditors lose confidence
  • Shareholder disputes if ownership records are altered
  • Tax authority investigations if profit figures are falsified

Small businesses bear disproportionate risk: Larger corporates employ dedicated compliance and IT teams to monitor accounts and respond to threats. Early-stage founders and small business owners often manage their Companies House accounts themselves, with limited technical knowledge or resources to detect and respond to compromises.

Longer-Term Fixes: What Needs to Change

Several structural improvements would reduce the risk of similar incidents:

Mandatory two-factor authentication: Rather than offering 2FA as an optional enhancement, Companies House should require it for all users. This would eliminate a large class of account takeover attacks at a stroke, though it would increase onboarding friction.

Notification and verification for high-risk actions: Filing changes to directors or registered office should trigger SMS or email verification codes, similar to banking applications. This would catch most account hijacking attempts in real time.

Biometric login options: For users with smartphones, facial recognition or fingerprint authentication could replace passwords entirely, eliminating password-based attacks. UK Government Digital Service guidance on identity verification is moving toward this model for digital identity systems.

Regular penetration testing: Companies House should commission independent security assessments at least quarterly and publish anonymised findings to demonstrate active security posture.

Cyber insurance and user indemnity: The government could offer a limited indemnity scheme for fraudulent filings caused by system vulnerabilities, reducing financial exposure for small businesses unable to afford D&O insurance.

Forward-Looking Analysis: The Road Ahead for UK Business Registry Security

The Companies House vulnerability is not an isolated incident—it reflects broader challenges in UK public digital infrastructure. As regulatory requirements increase (accounting standards, ESG reporting, corporate transparency initiatives), the registry will handle more data and attract greater interest from bad actors.

Emerging threats: As machine learning and AI tools improve, automated attacks against business registries will become more sophisticated. Attackers can now use publicly available company data to generate convincing social engineering attacks or credential guessing at scale. The Companies House vulnerability demonstrated that even officially-operated registries can have significant security gaps.

Regulatory pressure and reform: This incident will likely prompt Parliamentary scrutiny and calls for stronger oversight of Companies House operations. The Parliament Business, Energy and Industrial Strategy Committee has already examined Companies House reform, and security breaches will accelerate reform timelines.

Opportunities for startups:**This vulnerability created a market opportunity for third-party compliance and monitoring services. Several UK startups now offer automated monitoring of Companies House records, fraud detection, and account security solutions specifically designed to protect small businesses. For founders building compliance or cybersecurity tools, this incident validates market demand.

Immediate outlook (next 6 months): We can expect continued vigilance from Companies House, further communications to affected users, and possible compensation schemes for businesses that suffered demonstrable losses due to fraudulent filings. Founders should remain cautious and implement the recommended security measures immediately.

For UK founders, the lesson is clear: even government-operated systems are not immune to security flaws. Taking personal responsibility for account security—strong passwords, multi-factor authentication, regular monitoring—remains the most effective defense. While Companies House works to improve infrastructure, your business's protection depends on your own due diligence.