The Government Built the Best OSINT Database in the World and Called It Transparency

Opinion

The Government Built the Best OSINT Database in the World and Called It Transparency

I want to say something that people who work in government and policy circles generally avoid saying because it is uncomfortable.

The UK government has built one of the most comprehensive open source intelligence databases in the world, made it mandatory for millions of directors to populate, made it free to search and query via API, and then expressed mild concern when attackers use it to target those same directors.

They call it Companies House. They call it transparency. Both things are true and neither one fully excuses the other.

The Database Nobody Calls a Database

Companies House holds structured information on every limited company in the UK. Director names. Addresses. Persons with significant control. Filing history. Accounts. Confirmation statements. Charges. The date the company was incorporated. Historic officer changes. Previous addresses.

It is searchable online for free. It offers a documented API with a rate limit of 600 requests per five minutes. That rate limit is meaningful for bulk scraping. It is irrelevant to an attacker researching one specific director.

You are legally required to file this information. The Companies Act 2006 mandates it. Non-compliance carries penalties. There is no opt-out from the filing obligation. You can incorporate a company and have your name attached to it on a public register whether you want that or not.

For most legitimate purposes, this is reasonable. Corporate accountability matters. Fraud prevention matters. Credit checking matters. Journalists investigating rogue directors need public records. All of that is real.

But personal exposure is not the same thing as business transparency. And at some point, someone in government needed to sit down and ask: what happens when the same information that serves all those legitimate purposes is also used by criminals to target directors?

The answer appears to be: we will create a suppression service.

The Suppression Service Nobody Knows About

From 27 January 2025, Companies House introduced new measures allowing directors to remove home addresses from historical filings where those addresses were previously used as the registered office. This is a genuine improvement. It extends existing suppression rights under the Economic Crime and Corporate Transparency Act 2023.

The process costs £30 per application. You must first update the live registered office to a non-residential address before suppression of historical records can be applied for. Processing takes time. The result is that historical filings show a service address rather than your home.

How many of the roughly 4.5 million people registered as directors at Companies House know this service exists? I have no official figure. In conversations with SMB owners and their accountants throughout this series, the answer has consistently been: not many.

A suppression service that exists but is not widely known, that requires a prior administrative step to use, that costs £30 per application, and that only addresses historical records while leaving the present Companies House record and all existing data broker copies untouched is not a solution. It is a partial administrative fix that the beneficiaries largely have not been told about.

The Digital Glitter Problem

Here is the thing the suppression service cannot address.

Once your home address was published on Companies House, it was available. Data brokers, commercial intelligence providers, people-search sites, and marketing database companies may have taken copies. Those copies exist in their systems. Suppressing the Companies House record does not reach those copies.

The ICO found in its 2020 investigation that between Experian, Equifax, and TransUnion, the data of almost every adult in the UK was being screened, traded, profiled, enriched, or enhanced for commercial purposes, often sourced originally from public registers. Companies House is one of those public registers. The data flows from there into commercial products that are sold, resold, and retained indefinitely.

Digital glitter. Once it lands, it does not disappear because the source was swept.

What Honest Policy Would Acknowledge

I am not arguing that Companies House should be abolished or that corporate transparency is wrong.

I am arguing that a system designed for accountability should not be designed in a way that creates unnecessary personal risk for the individuals it captures. Those two goals are not mutually exclusive.

Business identity and personal identity are different things. A company’s registered office does not need to be the director’s home address. Directors could use professional service addresses, virtual office providers, or registered agent addresses. Many already do. But nothing in the system meaningfully pushes them toward doing so, and historically nothing prevented using a home address as the path of least resistance.

The NCSC, in its guidance on reducing digital footprints, recommends that directors avoid using home addresses as company service addresses. That is good advice published in a place that requires active searching to find. It is not prominently presented as part of the company formation process.

If the government is serious about reducing the attack surface for UK directors, the right interventions are structural, not reactive. Prominently advise new directors against using home addresses at point of formation. Expand suppression services and make the process faster and cheaper. Fund awareness campaigns through Companies House itself. Treat the exposure as a cybercrime risk and resource accordingly.

Who Bears the Cost

The fraud enabled by public director data does not cost the government. It costs the director who was impersonated, the business whose payment was redirected, the employee who was manipulated, and the bank that has to adjudicate the claim.

The cost of prevention is largely pushed to the individual: find the suppression service, pay the £30, opt out of the open electoral register, audit your data broker exposure, submit erasure requests, repeat in ninety days.

That is a reasonable set of expectations for someone who has been made aware of the problem. It is an unreasonable set of expectations for the millions of directors who have not.

Policy that creates risk and places the remediation cost entirely on those exposed is not transparency. It is externalisation.

What Needs to Change

Three specific asks for government and Companies House.

Make address suppression prominently visible at the point of company formation, not buried in guidance pages. New directors should understand the privacy implications of their address choices before they file, not years later when they discover the problem.

Make the suppression process free, faster, and more prominently advertised to existing directors. £30 is not prohibitive. It is a friction cost on a process most people do not know exists.

Commission and publish research on how public register data feeds into fraud and social engineering against UK SMBs. Treat this as the cybercrime data it is. Right now it is invisible in the official statistics because nobody is connecting the public data publication to the downstream fraud.

I am not holding my breath. But those three asks are simple, proportionate, and entirely within the government’s power. The cost of not acting is carried by the directors who get defrauded. That should appear somewhere in the policy calculation.

How to Turn This Into a Competitive Advantage

For advisers and MSPs, the Companies House and electoral register gap is a concrete, actionable engagement. Walking a client through what their own public profile looks like, helping them apply for address suppression, and opting them out of the open register is a service most competitors do not offer. It is also a natural gateway into broader security governance conversations.

For business owners, engaging with this issue publicly, through trade associations, in procurement conversations, and in supplier questionnaires, signals a level of security maturity that distinguishes you from competitors who have never considered it.

How to Sell This to Your Board

The government has built a mandatory public disclosure system that creates measurable fraud risk for directors. That is not an abstract concern. UK Finance publishes data annually on mandate fraud and authorised push payment fraud against UK businesses. A portion of that starts with OSINT reconnaissance enabled by public register data.

The fix costs almost nothing. Electoral register opt-out: free. Companies House suppression: £30. The awareness campaign to tell your directors it exists: one email. Present the risk and the remedy together and ask the board to assign accountability for completing the audit.

What to Do This Week

  1. Go to Companies House and search every director’s name. Document every address field.
  2. Apply for suppression of any home addresses that appear in historical records, after updating the live registered office.
  3. Opt every director out of the open electoral register.
  4. Write to your trade association and ask what their position is on director data exposure.
  5. Forward this article to your accountant and ask whether they advised you about address exposure when you incorporated.
SourceArticle
Companies HouseRemove your home address from the Companies House register
GOV.UKEconomic Crime and Corporate Transparency Act 2023
NCSCDefending against social engineering
Privacy InternationalUK regulator takes enforcement action against data brokers
Action FraudMandate fraud: how to protect your business
GOV.UKCyber Security Breaches Survey 2025/2026

Filed under

  • smb-security
  • uk-business
  • compliance-failure
  • executive-security
  • business-risk
  • data-protection
  • public-sector-security