Why Digital ID Is a Serious Security Threat For All

UK Digital ID Security Failures: Your Data Will Be Stolen

This morning, I got another spoof email. One of those obvious scam attempts pretending to be from somewhere I’d recognise. What wasn’t obvious was the email address they sent it to: an admin@ address on one of my less common domains, one I only use for financial admin stuff like PayPal and Stripe. Not a dot com. Not even a dot co.uk. Someone either scraped that address from somewhere it shouldn’t have leaked from, or they’re running sophisticated domain-guessing operations. Either way, it proves the point: nothing is safe. Not my obscure email addresses, not your passwords, and certainly not the massive centralised biometric database the UK government wants to build.

Your Biometric Data Will Be Stolen

On 18 November 2025, Companies House begins mandatory identity verification for millions of directors and people with significant control. They’re funnelling everyone through GOV.UK One Login, a system that security experts have already torn apart for failing basic cybersecurity standards. The government’s pitching this as convenience and fraud prevention. What they’re actually building is a honeypot containing biometric data, identity documents, and access credentials for six to seven million people, all sitting behind a login system that couldn’t pass its own security audits.

When your email gets compromised, you change your passwords and move on. When your fingerprints get stolen, you’re stuffed permanently. You cannot change your face. You cannot reset your iris patterns. Biometric breaches are forever.

The Security Failures Already Baked In

GOV.UK One Login hasn’t met the government’s own cybersecurity standards, yet they’re pressing ahead anyway. Security consultancy Cyberis conducted red team testing in March 2025 and found critical vulnerabilities allowing privileged access to be compromised without triggering security monitoring tools. The Department for Science, Innovation and Technology asked Computer Weekly not to reveal full details whilst they scrambled to fix it. That’s the system already serving six million users and providing access to over 50 government services.

A whistleblower’s data showed over 500,000 system vulnerabilities, thousands rated as critical or high severity. The platform meets only 21 of 39 outcomes under the National Cyber Security Centre’s Cyber Assessment Framework. It lacks Privileged Access Workstations, which the NCSC recommends for secure system administration. It has overseas admin access and insecure logins for live environments. In November 2022, the Cabinet Office flagged serious data protection failings. In September 2023, the NCSC warned of significant architectural shortcomings that could leave One Login vulnerable to identity theft.

Michael Perez from Ekco was blunt about it: requesting millions of individuals to submit sensitive identity documents via a platform that hasn’t fully adopted secure-by-design principles introduces significant risk. Jonathan Frost from BioCatch, who spent years at the City of London Police’s National Fraud Intelligence Bureau, warns that the phased 12-month rollout for existing directors creates a clear window for criminals to exploit during the transition.

The system even lost its certification under the Digital Identity and Attributes Trust Framework. Technically that happened because a key supplier let their certification lapse, but it demonstrates the fragility of the supply chain and governance holding this thing together.

The Permanent Problem With Biometric Data

In August 2019, researchers found that the BioStar 2 security platform had left over 1 million people’s fingerprints and facial recognition data completely unprotected and mostly unencrypted. Anyone could access 27.8 million records, view plain-text administrator passwords, track people’s movements in real-time, and even add new users. Tim Erlin from Tripwire made the obvious point: you can change a password, but you can’t change your biometric data.

More recently, Indian police biometric data leaked online. Roughly 500 gigabytes and 1.6 million documents from 2021 onwards, including fingerprints, facial recognition images, signatures, and tattoo descriptions. Cybercriminals started flogging similar data on Telegram. A US government database lost over 5 million fingerprints. The German Minister of Defence had their fingerprints lifted from high-resolution photos and used to beat authentication systems. Researchers have used Facebook photos to defeat facial recognition.

BioCatch’s research puts it plainly: biometric data security is permanent. Once stolen, it cannot be changed. Unlike passwords which can be reset after a breach, compromised biometric data remains a vulnerability for life. You get one set of fingerprints, one face, one set of iris patterns. When those leak, you’re permanently compromised across every system that uses biometric authentication.

TechUK’s 2023 research found that 95% of consumers believe biometrics are the most secure method for online accounts. Half now value their biometric data as important, up from 43% in 2022. That rising trust makes the risk even more dangerous, because people will assume their biometric-protected accounts are safe when the underlying database has already been breached.

Creating the Perfect Target

Every security expert worth listening to will tell you the same thing: centralised databases holding sensitive personal information are irresistible targets. Right now, if someone wants your data, they need to hit multiple systems. Your passport details live in one place, your driving licence in another, your medical records somewhere else, your financial information scattered across various institutions. Each breach is limited in scope.

Digital ID centralises everything. One login gives access to government services, proves right to work, potentially links to financial accounts, health records, and every interaction with public and private sectors. That’s not just convenient for you. It’s spectacularly convenient for anyone who manages to breach it.

The Tony Blair Institute has been pushing hard for this system, claiming it could deliver £2 billion annually through reduced benefit fraud, additional tax revenue, and better-targeted crisis support. Running costs estimated at just £100 million yearly. They point to Estonia as the success story where citizens save hours monthly on bureaucracy. What they don’t mention is that even Palantir, the surveillance company that built half the Western world’s intelligence infrastructure, has backed away from endorsing digital IDs. One executive called them “very controversial.” When Palantir thinks your surveillance system is dodgy, you should probably reconsider.

The Argument For Convenience Falls Apart

To be fair, the current system is genuinely annoying. When you apply for jobs or rent a flat, you’re sending full passport scans as PDFs to multiple parties. Anyone receiving those can forward them and digitally impersonate you. A properly designed digital ID could create time-limited verification statements instead of broadcasting your entire identity document. That would actually be better than the current mess.

But convenience doesn’t matter if the system isn’t secure. The government claims digital credentials stored on your device are safer than physical documents because they can be revoked and reissued if your phone is lost. They say it uses state-of-the-art encryption similar to banking apps. These are the same people who couldn’t secure the authentication gateway properly, who let critical vulnerabilities sit unpatched in live systems, who failed their own cybersecurity audits. Banks invest massive sums double-checking Companies House data because it’s already unreliable. The National Economic Crime Centre warned that improper use of companies creates substantial money laundering risk. Nothing about the current implementation suggests they’ve got security sorted.

The government promises physical alternatives, face-to-face support, and dedicated casework for people without smartphones or technical skills. They claim 10% of UK citizens have never had a passport whilst 93% own smartphones, positioning this as an inclusion measure. That might sound reasonable until you consider that elderly people and those who prefer not to use smartphones will be functionally excluded from an increasing number of services as the system expands.

They Already Have Your Data, Right?

This is the argument that keeps popping up in forum discussions and Reddit threads. The government already has your passport details, driving licence, National Insurance number. You’ve already given this data to various departments. So what’s the difference if it’s centralised?

The difference is catastrophic failure modes. Right now, if one system gets breached, the damage is contained. Your passport details leak from one database, your medical records from another. Each breach is terrible but limited. Centralising everything means a single breach exposes everything about you simultaneously. Your biometric data, your financial links, your medical history, your movement patterns, every interaction with government and potentially private services, all connected through one compromised login.

Traditional ID cards can be lost or forged, but when that happens you only lose the card itself. Not all the interconnected data and access points attached to a digital identity. A physical passport lives in your drawer most of the time. Digital ID becomes the key to everything, everywhere, constantly. You’re carrying the master key to your entire administrative existence on your phone, secured by a government system that couldn’t pass its own security checks.

Surveillance Infrastructure and Usage Creep

Even if you trust the current government’s intentions (which, given the security failures, you probably shouldn’t), you’re building permanent infrastructure that any future government can exploit. Digital ID creates the technical apparatus for unprecedented monitoring of citizens’ activities. By centralising and digitising personal data, the state gains ability to track where people work, access services, travel, and interact with both public and private sectors.

This represents a cultural shift away from minimal state intrusion into private life. Proponents point to existing forms of identification like passports and driving licences, but these aren’t required at every turn nor centrally linked across all domains. Digital ID sets a precedent for ever-expanding data collection, a future where privacy must be “granted” by those controlling the system rather than assumed by default.

Liberty and Big Brother Watch have both raised serious concerns about the mass surveillance infrastructure this creates. Big Brother Watch called the plans “wholly unBritish” and warned of creating a “domestic mass surveillance infrastructure.” The Westminster debate on digital ID in October 2025 was criticised for being undermined by lack of data and listening to civil liberties concerns.

The government announced this on 26 September 2025, during parliamentary recess, meaning MPs haven’t been given dedicated time to respond properly. A petition against mandatory digital ID has reached 2,912,390 signatures as of October 2025. That’s not fringe conspiracy theorists. That’s nearly three million people who understand that once you build surveillance infrastructure, it doesn’t get voluntarily dismantled.

The Mandatory But Not Mandatory Doublespeak

The government’s messaging is deliberately contradictory. They say obtaining digital ID won’t be compulsory, but it will be mandatory for some applications. By the end of this Parliament, employers must check it for right to work. From 18 November 2025, new directors need it to incorporate a company or be appointed to existing companies. Existing directors must confirm verification when filing their next annual confirmation statement. People with significant control must verify their identities.

So it’s not mandatory, except when it is. You’re free not to have one, as long as you don’t want to work, run a company, or access an increasing list of government services. That’s not voluntary. That’s compulsory with extra steps.

The latest government survey indicates 81% of respondents support implementing a new identity verification process. That statistic needs context. People support better verification because the current system is rubbish and fraud is a real problem. What they’re not being asked is whether they trust the government to build and secure a massive centralised biometric database without it getting breached within the first few years of operation.

What Happens Next

From 18 November 2025, this rolls out whether you like it or not. Companies House will contact companies to explain what directors and PSCs need to do. You verify through GOV.UK One Login (free and supposedly quick) or through an Authorised Corporate Service Provider. Once verified, you receive a personal code. From November onwards, you need to provide that code and a verification statement for each company role you hold.

In most cases, verification is supposedly a one-off process taking a few minutes. Companies House CEO Louise Smyth says identity verification will play a key role in improving data quality and tackling misuse of the companies register. She encourages people to verify as early as possible. What she doesn’t mention is that they’re funnelling millions through a system that failed security audits, lost its certification, and has over half a million unresolved vulnerabilities, thousands rated critical.

Users are already reporting problems on Reddit and forums. Confusion over passwords, verification failures with no explanation, systems appearing to still be in beta. One person compared it to the Post Office IT scandal. Another pointed out that if a bank rolled out a system this dysfunctional, they’d struggle to attract new customers.

The 12-month window for existing directors and PSCs to verify creates an obvious exploitation period. Criminals will target the transition, filing fraudulent documents whilst the system is still fragmented and verification requirements aren’t universal. Banks already know Companies House data is unreliable, which is why they spend fortunes double-checking everything. This rollout doesn’t fix that problem. It just creates new attack vectors.

The Reality Nobody Wants to Admit

The answer to “how would a database containing biometric and private data be private and safe” is simple: it wouldn’t be. Every historical example demonstrates that centralised data stores get breached, exploited, or misused eventually. The more valuable and comprehensive the data, the more attractive the target becomes. Your scraped email address is irritating. Leaked biometric data linked to your financial accounts, health records, movement patterns, and every interaction with government and private services would be catastrophic and permanent.

The government has proven they cannot secure the authentication gateway properly, let alone protect the treasure trove of sensitive data they’re planning to collect. They’ve failed their own cybersecurity standards, lost their security certification, left critical vulnerabilities unpatched in live systems, and are now mandating that millions of people submit biometric data and identity documents through this shambles.

None of this is theoretical. The breaches have already happened elsewhere. The vulnerabilities have already been found in this system specifically. The infrastructure for surveillance and control is being built right now, during parliamentary recess, without proper debate, despite nearly three million signatures opposing it.

When this database gets breached, and it will get breached, you cannot change your fingerprints. You cannot reset your face. You will be permanently compromised across every system that uses biometric authentication, forever. That’s not scaremongering. That’s the simple technical reality of what happens when immutable identifiers get stolen.

The convenience of one login isn’t worth building a surveillance state on a foundation of known security failures. Sometimes the annoying, fragmented, bureaucratic mess is actually safer than the tidy, centralised, “efficient” alternative. Your obscure email address got scraped. Imagine what happens when everything that identifies you sits in one massive, poorly-secured database that every hostile actor on the planet wants to breach.

Questions That Need Answering About Digital ID

Is GOV.UK One Login Actually Mandatory for Company Directors?

Yes, despite the government claiming digital ID is voluntary. From 18 November 2025, all new directors must verify their identity through GOV.UK One Login or an authorised service provider before being appointed. Existing directors must verify when filing their next annual confirmation statement, giving them up to 12 months to comply.

What Happens If My Biometric Data Gets Stolen in a Breach?

You’re permanently compromised because you cannot change your fingerprints, face, or iris patterns like you can reset a password. Every system that uses biometric authentication becomes a security risk for the rest of your life. Historical breaches have seen stolen biometric data sold on criminal marketplaces and used to defeat authentication systems.

Can I Still Run a Company If I Refuse to Get a Digital ID?

Technically no, though the government won’t phrase it that way. Without verified identity through GOV.UK One Login or an authorised provider, you cannot be appointed as a director or person with significant control. You also cannot file required documents like confirmation statements, effectively blocking you from legally operating a company.

Has GOV.UK One Login Passed Security Audits?

No, it has failed to meet the government’s own cybersecurity standards. Security testing in March 2025 found critical vulnerabilities allowing privileged access to be compromised without triggering security monitoring. The system meets only 21 of 39 outcomes under the National Cyber Security Centre’s Cyber Assessment Framework and has over 500,000 system vulnerabilities, thousands rated critical or high severity.

What Alternatives Exist If I Don’t Have a Smartphone?

The government promises physical alternatives and face-to-face support, though details remain vague about how this will work in practice. You can also verify through Authorised Corporate Service Providers, though these may charge fees. The reality is that as more services require digital ID, people without smartphones or technical skills will face increasing exclusion from essential functions.

Why Is the Government Rushing This Through During Parliamentary Recess?

The announcement came on 26 September 2025 whilst Parliament was not sitting, meaning MPs haven’t been given dedicated time to properly debate or scrutinise the rollout. Nearly three million people have signed a petition opposing mandatory digital ID, yet the 18 November implementation date proceeds regardless. This pattern suggests the government wants to establish the system before opposition can organise effectively.

Can Biometric Data Actually Be Encrypted Securely Enough to Prevent Breaches?

The BioStar 2 breach in 2019 proves the answer is no, not when human error and poor security practices are involved. That system left over 1 million fingerprints and facial recognition records completely unprotected and mostly unencrypted. Even with strong encryption, if administrators have overseas access, use insecure logins for live environments, and leave critical vulnerabilities unpatched, the encryption becomes irrelevant when attackers exploit those weaknesses instead.


Sources – Yes, Lots of Sources!

Companies House confirms identity verification rollout from 18 November 2025
gov.uk

Making identity verification simple, secure and trusted
companieshouse.blog.gov.uk

Access to Companies House WebFiling accounts to move to GOV.UK One Login
gov.uk

Identity verification – Changes to UK company law
changestoukcompanylaw.campaign.gov.uk

Companies House ID verification rollout to impact millions
businesssurrey.co.uk

Petition: Do not introduce Digital ID cards
petition.parliament.uk

Security tests reveal serious vulnerability in government’s One Login digital ID system
computerweekly.com

Mandatory ID verification will come into effect on 18 November 2025
vwv.co.uk

Stuart Anderson MP Opposes Mandatory Digital ID
stuartanderson.org.uk

UK One Login Digital ID System Faces Major Security Breach Allegations
idtechwire.com

Companies House confirms mandatory identity verification from 18 November 2025
penningtonslaw.com

Hold a referendum on introducing mandatory identity cards in the UK
petition.parliament.uk

Government under fire over security of identity verification system
thinkdigitalpartners.com

Get ready for identity verification at Companies House
firstaml.com

Government’s One Login System Loses Key Security Certification
bramblehub.co.uk

UK Digital ID
en.wikipedia.org

Critical Security Flaw Found in UK’s Gov.uk One Login Identity System
idtechwire.com

LIBERTY’S POSITION ON DIGITAL ID
libertyhumanrights.org.uk

Digital ID: Why It Should Be Opposed
theemploymentlawsolicitors.co.uk

Digital ID cards could be a disaster in the UK and beyond
newscientist.com

Digital Identity Sectoral Analysis 2025
gov.uk

Digital ID launch marks major shift but risks and questions remain
ukauthority.com

Experts Alarmed by UK Government’s Companies House ID Plans
infosecurity-magazine.com

How worried should you be by the BioStar 2 breach that leaked 1 million people’s biometric data
itgovernance.co.uk

What the UK’s worst data breaches say about Government plans for a digital ID system
bigbrotherwatch.org.uk

Concerns grow over UK digital ID checks for company directors
itbrief.co.uk

A Leak of Biometric Police Data Is a Sign of Things to Come
wired.com

First Westminster debate on UK digital ID undermined by lack of data listening
biometricupdate.com

Companies House security concerns with GOV.UK One Login
westonfinancialltd.co.uk

Biostar security software ‘leaked a million fingerprints’
bbc.co.uk

What Happens If Biometric Data Is Breached (And How To Prevent It)
forbes.com

Companies House starts to verify identities
gov.uk

Kaspersky finds 24 vulnerabilities in Chinese biometric access systems
kaspersky.com

Companies House One Login
friendandgrant.co.uk

Digital ID scheme: explainer
gov.uk

New digital ID scheme to be rolled out across UK
gov.uk

Time for Digital ID: A New Consensus for a State That Works
institute.global

How the government’s new digital ID will work
takes.jamesomalley.co.uk

Turning tables: the rising trust in biometrics
techuk.org

What Is the UK Government’s Digital ID Plan and Why Now?
merrantiaccounting.com

Anyone else having issues with getting into Companies House?
reddit.com

UK Digital ID – Pros and Cons of BritCard
securityjournaluk.com

Ready or informed or not, here comes UK’s national digital ID debate
biometricupdate.com

Counterpoints to “we already give them our data anyway”
reddit.com

What is the plan for digital IDs and will they be mandatory?
bbc.co.uk

Digital ID in the UK: what comes next? A techUK perspective
techuk.org

Verifying identity on Companies House with GOV.UK One Login
jakelee.co.uk

What’s up with the new digital ID card system in the UK?
reddit.com

What can we do to avoid the new digital ID?
reddit.com

What are the pros and cons with Digital IDs?
reddit.com

Arguments against digital ID are paper thin
reddit.com

Digital ID cards ‘will not restrict use of public services’
reddit.com

Stolen fingerprints could spell the end of biometric security
theconversation.com

People in countries with digital IDs, what’s it’s like?
reddit.com

How to verify your identity (IDV) at Companies House
ttca.co.uk

Balancing the promise and risks of physical biometric authentication
biocatch.com

Those in favour of the Digital ID. What are the benefits?
reddit.com

Verifying your identity for Companies House
gov.uk

Biometric Identification: The Good and The Bad
digitalskills.miami.edu

From what you have seen or heard, do you support or oppose the introduction of digital ID cards?
yougov.co.uk

Biometrics and Privacy: Issues and Challenges
ovic.vic.gov.au

Common Identity Verification Issues & How to Solve Them
ukpropertyaccountants.co.uk

Biometric Security Pros and Cons in Cyber Protection
keepnetlabs.com

My writing:

I don’t write for the algorithms here. I write for you, the reader. So I am so grateful for your time. Thank you for reading.

Comments:

To keep this site free from spam, comments have been turned off. You are very welcome to contact me via my Facebook profile using the link in the footer.

About me…