Companies House "hack"
Author
Discussion

selwonk

Original Poster:

2,143 posts

248 months

Friday 13th March
quotequote all
Sorry it this has been posted elsewhere; I know there a number of threads running on Digital ID etc.

This is astonishing:

https://taxpolicy.org.uk/2026/03/13/companies-hous...

In a nutshell, an exploit has been identified in the Companies House web site. Hack is a strong word:

1. Log into your own company dashboard.
2. Click the link to file for another company.
3. Enter the publicly available company number.
4. Proceed.
5. You are presented with a authentication code input.
6. Press the browser back button four times.
7. You are back on the company dashboard, but not your own. Instead you are in the company dashboard of the company number you entered in step 3,.

Those of us opposed to Digital ID and, pretty much, any large Gov.UK IT project are repeatedly told that we a paranoid and yet they cock it up time after time after time!

mattley

3,030 posts

245 months

Saturday 14th March
quotequote all
If you can perform Step 1 you're already compromised.

https://www.computerweekly.com/news/366623991/Secu...

This is how they hide this awfulness

https://committees.parliament.uk/writtenevidence/1...


Tim Cognito

990 posts

30 months

Saturday 14th March
quotequote all
That is absolutely mind-blowing from a security perspective if true.

jesusbuiltmycar

5,069 posts

277 months

Sunday 15th March
quotequote all
Might be worth emailing The Register and tipping them off - I am sure there Cyber Security team would to love to have a play and write n article about it.

davek_964

10,711 posts

198 months

Monday 16th March
quotequote all
mattley said:
If you can perform Step 1 you're already compromised.
I don't think so. Step 1 is logging into your own account. But following the steps, you could then access any other company account that is nothing to do with you.

GlenMH

5,413 posts

266 months

Monday 16th March
quotequote all
The Register have already run with it: https://www.theregister.com/2026/03/16/companies_h...

And it has only been there since October 2025 yikes

And we are being asked to trust these clowns with our digital ID??

Edited by GlenMH on Monday 16th March 13:50

jesusbuiltmycar

5,069 posts

277 months

Monday 16th March
quotequote all
Now on BlackBeltBarrister


selwonk

Original Poster:

2,143 posts

248 months

Monday 16th March
quotequote all
The exploit has been in the wild for five months and every company was vulnerable.