Companies House Security Breach

Ozzy

Founder of UKBF
UKBF Staff
  • Feb 9, 2003
    8,314
    11
    3,434
    Northampton, UK
    bdgroup.co.uk
    This doesn't make great reading;


    So on Friday a really simple way to breach confidential director information was made public, which as it turns out had been in place for ~5 months based on the official statement published today by Companies House themselves.


    Personally find that is actually really scary how simple it was to circumvent and gain access to other company information, and the ability to file any form on behalf of any company! Just pressing back on the web browser four times once you reach the page where you are asked for the authentication code for adding a new company to your web filing account (only sharing this now that they confirm it has been fixed)
     

    Ozzy

    Founder of UKBF
    UKBF Staff
  • Feb 9, 2003
    8,314
    11
    3,434
    Northampton, UK
    bdgroup.co.uk
    I feel it's more to do with the push to rush stuff out the door than actual capability. I know many of the people at Companies House and they are very talented, but goes back to the old;
    You can have it cheap, quick or good quality - pick the two you want.
     

    Karimbo

    Free Member
  • Nov 5, 2011
    2,697
    1
    353
    companies house insist that it is a tedious hack and can only get 1 company at a time, and not a broad tool where hackers just extract the entire database in one go.

    I can tell you that it's not going to be difficult of a task for a hacker to use sql injection to get all the companies house details one by one over time. Just run a script to automate this.

    Dont think of yourself as safe if no details have been chnaged. With the directors DOB and home address, it's possible for any criminals to open a business bank account and get a business loan deposited to the bank account and cause some serious damage.
     
    • Like
    Reactions: Ozzy

    Latest Articles