英国的数据缺陷让用户通过浏览器后端按钮访问其他公司的机密信息,导致系统关闭和调查。
A UK data flaw let users access other companies' confidential info via the browser back button, prompting a system shutdown and investigation.
2025年10月的软件更新可能造成英国公司之家 WebFinging系统的安全缺陷,允许登录用户使用浏览器的后键访问和编辑其他公司的机密数据。
A security flaw in the UK’s Companies House WebFiling system, likely caused by an October 2025 software update, allowed logged-in users to access and potentially edit other companies’ confidential data using the browser’s back button.
这个问题暴露了诸如董事的出生日期、地址和电子邮件地址等敏感细节,尽管密码和身份证件没有被泄露。
The issue exposed sensitive details like directors’ dates of birth, addresses, and email addresses, though passwords and identity documents were not compromised.
可能已经提交了未经批准的文件,但现有的文件没有被更改。
Unauthorized filings may have been submitted, but existing filed documents were not altered.
税务专业人员Dan Neidle报告说,这项服务于3月13日暂停,并于3月16日恢复。
The service was suspended on March 13 and restored by March 16 after being reported by tax professional Dan Neidle.
公司事务所确认没有大规模或系统获取的证据,称未确认滥用情况,并正在通知所有注册公司,指导其审查记录。
Companies House confirmed no evidence of large-scale or systematic access, stated no misuse has been confirmed, and is notifying all registered companies with guidance to review their records.
Andy King首席执行官道歉,强调正在进行的调查以及对透明度和安全的承诺。
CEO Andy King apologized, emphasizing ongoing investigations and a commitment to transparency and security.