Companies House "hack"
Author
Discussion

selwonk

Original Poster:

2,143 posts

250 months

Friday 13th March
quotequote all
Sorry it this has been posted elsewhere; I know there a number of threads running on Digital ID etc.

This is astonishing:

https://taxpolicy.org.uk/2026/03/13/companies-hous...

In a nutshell, an exploit has been identified in the Companies House web site. Hack is a strong word:

1. Log into your own company dashboard.
2. Click the link to file for another company.
3. Enter the publicly available company number.
4. Proceed.
5. You are presented with a authentication code input.
6. Press the browser back button four times.
7. You are back on the company dashboard, but not your own. Instead you are in the company dashboard of the company number you entered in step 3,.

Those of us opposed to Digital ID and, pretty much, any large Gov.UK IT project are repeatedly told that we a paranoid and yet they cock it up time after time after time!

mattley

3,031 posts

247 months

Saturday 14th March
quotequote all
If you can perform Step 1 you're already compromised.

https://www.computerweekly.com/news/366623991/Secu...

This is how they hide this awfulness

https://committees.parliament.uk/writtenevidence/1...


Tim Cognito

1,034 posts

32 months

Saturday 14th March
quotequote all
That is absolutely mind-blowing from a security perspective if true.

jesusbuiltmycar

5,089 posts

279 months

Sunday 15th March
quotequote all
Might be worth emailing The Register and tipping them off - I am sure there Cyber Security team would to love to have a play and write n article about it.

davek_964

10,846 posts

200 months

Monday 16th March
quotequote all
mattley said:
If you can perform Step 1 you're already compromised.
I don't think so. Step 1 is logging into your own account. But following the steps, you could then access any other company account that is nothing to do with you.

GlenMH

5,423 posts

268 months

Monday 16th March
quotequote all
The Register have already run with it: https://www.theregister.com/2026/03/16/companies_h...

And it has only been there since October 2025 yikes

And we are being asked to trust these clowns with our digital ID??

Edited by GlenMH on Monday 16th March 13:50

jesusbuiltmycar

5,089 posts

279 months

Monday 16th March
quotequote all
Now on BlackBeltBarrister


selwonk

Original Poster:

2,143 posts

250 months

Monday 16th March
quotequote all
The exploit has been in the wild for five months and every company was vulnerable.