Davenports Accountancy

We bring you the best possible solutions for the growth and prosperity of your business or your personal finances.

You can’t go wrong with Davenports.

Latest Posts

0161 713 0157

hello@davenportsaccountancy.co.uk

Top

Companies House WebFiling shutdown traced to security flaw linked to Gov.uk One Login rollout

Companies House has acknowledged that the sudden suspension of its WebFiling service was caused by a security flaw that originated five months earlier, following IT changes made to support the Gov.uk One Login system, which replaced the Government Gateway.

 

The issue was identified on 13 March, prompting Companies House to shut down the WebFiling service at 1.30pm last Friday.

 

The flaw meant that users who were logged into WebFiling could, by clicking back from within their own company dashboard, view and amend certain details belonging to another company without authorisation.

 

Andy King, chief executive of Companies House, said:

 

‘This was not accessible to the general public. Only users with an authorised code and logged in to the service could have performed this action.’

 

Investigators later confirmed that the vulnerability was introduced during an update in October 2025, when Government Gateway access was replaced. This meant the system had been exposed for around five months before being detected.

 

The timing coincided with the launch of the Gov.uk One Login system on 13 October 2025, which required company directors to access WebFiling using the new single sign-on service rather than the existing Government Gateway credentials.

 

Although Companies House has sought to downplay the scale of the breach, it has confirmed that sensitive information including directors’ email addresses, residential addresses and dates of birth may have been visible to unauthorised users. Passwords and passport details were not affected. The WebFiling service was restored on Monday morning.

 

King said:

 

‘Our investigation has established that specific data from individual companies not normally published on the Companies House register may have been visible to other logged-in WebFiling users. This includes dates of birth, residential addresses and company email addresses.

 

It may also have been possible for unauthorised filings – such as accounts or changes of director – to have been made on another company’s record.

 

We want to be clear about what was not affected:

 

  • Passwords were not compromised;
  • No data used as part of our identity verification process, such as passport information, was accessed;
  • No existing filed documents, such as accounts or confirmation statements could have been altered.’

 

In an effort to reassure businesses, King added:

 

‘We believe that this issue could not have been used to extract data in large volumes or to access records systematically. Any access would have been limited to individual company records, viewed one at a time by a registered WebFiling user.’

 

What companies should do now

 

Businesses are being advised to review all information held at Companies House to confirm that no data has been altered or removed.

 

King stressed:

 

‘We are actively analysing our data to identify any anomalies, and we’ll be emailing every company’s registered email address to explain how to check their details and what steps to take if they have any concerns.

 

Companies should immediately check their registered details and filing history to make sure everything appears correct. If a company has a concern, please raise a complaint and include evidence to describe the concern’.

 

He added:

 

‘We have no reports at this stage of data having been accessed or changed without permission. However, our investigation is ongoing. We’ll provide further updates as our work progresses and we remain committed to being transparent throughout.

 

We’ll soon be publishing a page with more details to answer any further questions you may have.’

 

The breach has been reported to both the Information Commissioner’s Office (ICO) and the National Cyber Security Centre (NCSC).

 

King also issued an apology, stating:

 

‘I recognise that this incident will have caused concern and inconvenience to many of the companies and individuals who rely on our services. I am sorry for that.

 

Companies House takes its responsibility to protect the data entrusted to us extremely seriously. We have taken swift action to secure and restore our service, and are committed to doing everything in our power to support those affected and to making sure that our services continue to merit the trust placed in them.’

 

The incident is likely to raise concerns for HMRC, which is currently rolling out Gov.uk One Login as a replacement for the Government Gateway across its own services.

Author