Wow what a screw up from UK's Companies House discovered last week:

- Unauthorised access to any company’s dashboard
- Vulnerability existed since October 2025
- Bad actors could access non-public personal data
- Bad actors could file accounts and company/director changes

https://taxpolicy.org.uk/2026/03/13/companies-house-security-vulnerability-directors-addresses/

Is there anyone who can be trusted with PII?

#UK #Privacy #CompaniesHouse #PII

Companies House flaw exposed five million directors and enabled company hijacking

A major flaw in the Companies House website enabled free access to the “dashboard” of any of the five million registered companies. See it used in this video.

Tax Policy Associates