HomeIntelligenceBrief
🛡️ VULNERABILITY BRIEF🟠 High🔓 Breach

WebFiling Vulnerability Exposes UK Director Details and Enables Record Tampering

Companies House temporarily disabled its WebFiling service after discovering a flaw that let anyone view director personal details and modify company filings. The vulnerability was patched and the portal restored, but the exposure raises immediate third‑party risk concerns for organizations that rely on official UK company data.

🛡️ LiveThreat™ Intelligence · 📅 March 17, 2026· 📰 hackread.com
🟠
Severity
High
🔓
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
hackread.com

WebFiling Vulnerability Exposes UK Director Details and Enables Record Tampering

What Happened — A flaw in Companies House’s WebFiling portal allowed unauthenticated users to view personal director information and to alter company filing records. The service was taken offline, the vulnerability patched, and the portal restored.

Why It Matters for TPRM

  • Sensitive director data can be leveraged for social‑engineering attacks against third‑party vendors.
  • Unauthorized changes to company records create legal and compliance risks for partners that rely on official filings.
  • The incident highlights the need for continuous monitoring of government‑provided data sources.

Who Is Affected — UK‑registered companies, their directors, and any third‑party services that ingest Companies House data (e.g., credit‑risk platforms, compliance SaaS).

Recommended Actions

  • Review any reliance on Companies House data for due‑diligence or onboarding.
  • Implement additional verification of director information from independent sources.
  • Monitor the Companies House “WebFiling” service status and subscribe to change‑notification feeds.

Technical Notes — The issue appears to be an insecure direct object reference (IDOR) / improper access control flaw; no CVE has been assigned yet. Exposed data included director names, dates of birth, and appointment histories; altered data involved company filing entries. Source: HackRead

📰 Original Source
https://hackread.com/companies-house-webfiling-flaw-director-details/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

🛡️

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.