UK’s Companies House confirms security flaw exposed business data
嗯,用户让我帮忙总结一篇文章,控制在100字以内,而且不需要特定的开头。首先,我需要仔细阅读这篇文章,理解其主要内容。 文章讲的是英国政府机构Companies House的一个安全漏洞。这个漏洞导致五百万家公司信息在五个月内被泄露。攻击者可以通过登录自己的账户,然后选择为其他公司提交文件,输入目标公司的编号,绕过认证代码,直接访问其他公司的仪表盘。这暴露了管理者的家庭住址和邮箱等敏感信息。 修复这个漏洞后,他们已经将WebFiling服务恢复,并报告给了相关部门。目前还没有证据显示数据被滥用或更改。 接下来,我需要将这些信息浓缩到100字以内。要确保涵盖主要事件:漏洞的存在、影响范围、攻击方式、暴露的信息、修复措施以及当前情况。 可能会遇到的问题是如何在有限的字数内准确传达所有关键点。可能需要简化一些细节,比如省略攻击的具体步骤,只提到绕过认证即可。 最后,确保语言简洁明了,不使用复杂的术语,让读者一目了然。 </think> 英国政府机构Companies House因安全漏洞导致五百万家公司信息泄露五个月。攻击者可绕过认证访问其他公司仪表盘,暴露管理者的家庭住址和邮箱等敏感信息。该漏洞于2025年10月被修复后服务恢复运营,并已向相关部门报告。目前尚未发现数据被滥用或更改的证据。 2026-3-16 17:15:17 Author: www.bleepingcomputer.com(查看原文) 阅读量:2 收藏

Companies House

Companies House, a British government agency that operates the registry for all U.K. companies, says its WebFiling service is back online after it was closed on Friday to fix a security flaw that exposed companies' information since October 2025.

Dan Neidle, founder of the non-profit Tax Policy Associates, reported the vulnerability to the U.K. corporate register on Friday after Ghost Mail's John Hewitt (who discovered the flaw) didn't receive a reply.

"All that was required was to log in to Companies House using your own details and access your own company's dashboard. Then opt to "file for another company" and enter the company number for any one of the five million companies registered with Companies House," said Neidle.

"At that point you'd be asked for an authentication code, which of course you don't have. No problem. Press the 'back' key a few times to return to your dashboard. Except – it isn't your dashboard. It's the other company's dashboard."

Neidle added that the flaw exposed the data of five million registered companies for five months, including their management's home and email addresses.

Companies House confirmed the vulnerability on Monday after bringing the filing service back online and said that the issue was introduced when the agency updated its WebFiling systems in October 2025.

Dan Neidle Companies House post

The agency said the flaw could've been abused only by logged-in users and would've allowed them to "change some elements of another company's details without their consent." However, it also added that the security issue could only be exploited to steal data and access company records one entry at a time. 

"Our investigation has established that specific data from individual companies not normally published on the Companies House register may have been visible to other logged-in WebFiling users," Companies House noted

"This includes dates of birth, residential addresses and company email addresses. It may also have been possible for unauthorised filings — such as accounts or changes of director — to have been made on another company's record."

As the agency added, no user passwords were compromised, and data used during the identity verification process, such as passport information, was not accessed while the service was vulnerable. Additionally, "no existing filed documents, such as accounts or confirmation statements could have been altered."

The agency has since reported the incident to the U.K. Information Commissioner's Office (ICO) and the National Cyber Security Centre (NCSC), and is investigating if this vulnerability has been exploited to access or alter any company's details.

"We have no reports at this stage of data having been accessed or changed without permission," Companies House said in today's statement. "However, our investigation is ongoing. We'll provide further updates as our work progresses and we remain committed to being transparent throughout."

tines

Red Report 2026: Why Ransomware Encryption Dropped 38%

Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.


文章来源: https://www.bleepingcomputer.com/news/security/uks-companies-house-confirms-security-flaw-exposed-business-data/
如有侵权请联系:admin#unsafe.sh