Wow what a screw up from UK's Companies House discovered last week:
- Unauthorised access to any company’s dashboard
- Vulnerability existed since October 2025
- Bad actors could access non-public personal data
- Bad actors could file accounts and company/director changes
https://taxpolicy.org.uk/2026/03/13/companies-house-security-vulnerability-directors-addresses/
Is there anyone who can be trusted with PII?
