Compliance
ANALYSIS: Liechtenstein’s Cybersecurity Attack Part Of Global Trend
.jpg)
The incident, as disclosed by the European principality this week, is part of a pattern that continues to put compromises to privacy high up on the private banking and wealth management agenda. We list a few recent examples of where defences were broken.
As reported here, the Liechtenstein government has disclosed a major cybersecurity incident involving 31,000 legal entities on a register of beneficial ownership.
The saga shines a light on how government-run registers, databases and other information sources can be targeted. This raises uncomfortable questions on whether the drive for transparency on beneficial ownership data can clash with security of that information. With AI also intersecting with cybersecurity, and quantumn computing on the horizon, the stakes keep rising.
Revenue authorities in countries that have engaged in tax disclosure pacts with Liechtenstein, such as the UK and HM Revenue & Customs, will monitor the situation.
“It is not clear how and when any information obtained from this
latest data leak will be used. However, with Liechtenstein being
home to many low-tax trusts, one thing we can be sure of is that
HMRC will be watching developments closely," Alistair Culverwell,
partner and head of tax dispute resolution, Forvis Mazars, said
in an emailed statement to this news service.
The move will be a blow to Liechtenstein, a jurisdiction
that received a “Largely Compliant” rating from the OECD in
a report in June this year. The Paris-headquartered body, in
its Enhanced Monitoring Report on the Implementation of the
Standard on Transparency and Exchange of Information on
Request (EOIR), recommended that Liechtenstein should
“further strengthen” measures so that that beneficial ownership
information is available in respect of “all relevant entities and
arrangements as required under the standard.”
The OECD report made no reference to the cybersecurity angle. It
said that under new legislation, the Fiscal Authority
(Liechtenstein’s competent authority) has access to the
beneficial ownership register. The Financial Intelligence Unit,
the Financial Market Authority, the Prosecutors Office, the
Princely Court, the National Police, AML-obliged persons and the
Liechtenstein Bar Association (as a supervisory authority) also
have access to the register. Liechtenstein has taken
“comprehensive actions to address the recommendation and is no
longer required to report,” the OECD said, noting that a
“previous gap” in beneficial ownership information had been
closed by new legislation.
The Liechtenstein cybersecurity case is the latest in a
series of data leaks, including the Panama
Papers and the Paradise papers, both of which led to
HMRC opening probes into UK taxpayers.
When governments enter automatic exchange of information
agreements with the ostensible purpose of foiling tax evaders and
illicit financial flows, such incidents raise questions about
what happens if criminals and other hostile actors break into the
data "vaults," and where the liability rests? Some
countries, such as those in the European Union are under the
General Data Protection Regulation (GDPR) powers that went into
effect in 2018 (the UK remains under this, even after leaving the
EU). Certain states in the US, such as California, have a
version of GDPR, while the US as a whole so far doesn’t have this
at a federal level. (This
recent controversy about New York City Mayor Zohran Mamdani's
database on "pied à terre" homes also raises
questions about BO information.) Regulations elsewhere in the
world are patchy.
The editor of this news service examined a list of major
breaches and attacks on government data sources over the past six
months. Here are examples. Some of the cases are still live and
haven’t been fully resolved.
UK
The UK Companies House WebFiling case, which happened
in March. A vulnerability in CH’s WebFiling service, traced
to an October 2025 system update, let logged-in users view, and,
under some conditions potentially amend another
company's dashboard. This enabled changes to be made to data such
as directors' home addresses, dates of birth and emails. The
vulnerability was discovered between 12 and 13 March by a
corporate services researcher. Companies House took WebFiling
offline on 13 March and restored it on 16 March. CH said no
paswords, identity-verification data or filed documents had
been altered.
The Netherlands
On 19 March, the Ministry's ICT security team detected
unauthorised access to systems. A tip-off was received by
a third party who alerted the Ministry to suspicious
activity. Affected systems, including a Treasury banking portal,
were deliberately taken offline on 23 March to stop data being
exfiltrated.
Tax collection, customs and income-linked subsidy systems that
handled more than 9.5 million income tax returns a year were not
affected, reports said. The breach was reported to the Dutch
Data Protection Authority over possible exposure of employee
data. No group has claimed responsibility.
The Netherlands and EU
The European Commission, the Dutch Data Protection Authority
and Judicial Council were hacked. Work-related names, emails and
phone numbers were accessed in the Dutch incident, while the
Commission contained its breach within nine hours.
Sweden
The cybercrime group ByteToBreach reportedly stole Swedish
government data from its E-Gov platform.
Spain
Check Point Research identified a malicious email campaign
impersonating the Spanish tax authority, Agencia Tributaria
(AEAT), with a spoofed email sent to a Spanish industrial
company, carrying a trojan-downloader attachment, reports
said. This did not breach AEAT's own systems, but it was
part of a wider range of attacks.
General
Comparitech recorded 187 ransomware attacks on government
agencies worldwide in the first half of this year, rising 13 per
cent from the second half of 2025. Several of these attacks hit
agencies that hold tax and business-registration data at the
state/municipal level.
Hong Kong
Data on Asia breaches or attacks where governments acknowledge an
issue are less common, or not so widely reported in the media.
Hong Kong regulators (Hong Kong Monetary Authority and Securities
and Futures Commission) issued circulars in late May/early June
calling for enhanced cybersecurity measures against AI-enabled
cyberattacks.
Singapore
The Monetary Authority of Singapore has launched a task force to
tackle AI-driven attacks and strengthen cybersecurity.