A security vulnerability in the Companies House web filing system, present since October 2025, allowed logged-in users to access other companies' private dashboards through a simple sequence of actions.
The flaw, discovered on 12 March by John Hewitt at corporate services provider Ghost Mail, enabled access to non-public information, including directors' home addresses, email details and dates of birth.
Testing also suggested it may have allowed unauthorised users to file accounts or modify company information without the legitimate company owner receiving notification.
A poll conducted on the Enterprise Nation community hub found 76% of members were either concerned or very concerned about the news.
, founder of Brooks Business & Funding Solutions and an Enterprise Nation member, said: