The Containment Era is here. →Explore

Executive Summary

In March 2026, the UK's Companies House disclosed a significant security vulnerability in its WebFiling service, which had been present since October 2025. This flaw allowed authenticated users to access and potentially modify sensitive information of any registered company by exploiting a back-navigation loophole. The exposed data included directors' residential addresses, email addresses, and dates of birth. The agency has since rectified the issue, notified affected parties, and reported the incident to the Information Commissioner's Office (ICO) and the National Cyber Security Centre (NCSC). This incident underscores the critical importance of rigorous security testing and prompt response to vulnerabilities in public sector digital services. The exposure of personal data over an extended period raises concerns about potential misuse and the necessity for enhanced monitoring and compliance measures to protect sensitive information.

Why This Matters Now

The prolonged exposure of sensitive business data due to this vulnerability highlights the urgent need for continuous security assessments and robust access controls in government digital services. Organizations must prioritize the protection of personal information to maintain public trust and comply with data protection regulations.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The vulnerability exposed directors' residential addresses, email addresses, and dates of birth of registered companies.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to exploit vulnerabilities, move laterally, and exfiltrate sensitive data by enforcing strict segmentation and identity-aware policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to exploit the WebFiling service vulnerability would likely be constrained, reducing unauthorized access to company dashboards.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges and access sensitive information would likely be constrained, reducing unauthorized modifications.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's ability to move laterally within the system would likely be constrained, reducing unauthorized access to additional records.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to maintain persistent access would likely be constrained, reducing the duration of unauthorized control.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's ability to exfiltrate sensitive data would likely be constrained, reducing unauthorized data exposure.

Impact (Mitigations)

The attacker's ability to alter company records and expose sensitive information would likely be constrained, reducing the overall impact of the breach.

Impact at a Glance

Affected Business Functions

  • Company Registration
  • Filing of Annual Returns
  • Director Appointments
  • Registered Office Changes
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: N/A

Data Exposure

Personal identifiable information (PII) of company directors, including dates of birth, residential addresses, and company email addresses.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict access between services and prevent unauthorized lateral movement.
  • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to unusual access patterns promptly.
  • Enforce Egress Security & Policy Enforcement to monitor and control data exfiltration attempts.
  • Utilize Multicloud Visibility & Control to gain comprehensive insights into system activities and detect anomalies.
  • Regularly update and patch web applications to mitigate vulnerabilities and reduce the attack surface.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image