Compliance

ANALYSIS: Liechtenstein’s Cybersecurity Attack Part Of Global Trend

Editorial Staff 5 August 2026

ANALYSIS: Liechtenstein’s Cybersecurity Attack Part Of Global Trend

The incident, as disclosed by the European principality this week, is part of a pattern that continues to put compromises to privacy high up on the private banking and wealth management agenda. We list a few recent examples of where defences were broken.

As reported here, the Liechtenstein government has disclosed a major cybersecurity incident involving 31,000 legal entities on a register of beneficial ownership.  

The saga shines a light on how government-run registers, databases and other information sources can be targeted. This raises uncomfortable questions on whether the drive for transparency on beneficial ownership data can clash with security of that information. With AI also intersecting with cybersecurity, and quantumn computing on the horizon, the stakes keep rising.

Revenue authorities in countries that have engaged in tax disclosure pacts with Liechtenstein, such as the UK and HM Revenue & Customs, will monitor the situation. 

“It is not clear how and when any information obtained from this latest data leak will be used. However, with Liechtenstein being home to many low-tax trusts, one thing we can be sure of is that HMRC will be watching developments closely," Alistair Culverwell, partner and head of tax dispute resolution, Forvis Mazars, said in an emailed statement to this news service. 

The move will be a blow to Liechtenstein, a jurisdiction that received a “Largely Compliant” rating from the OECD in a report in June this year. The Paris-headquartered body, in its Enhanced Monitoring Report on the Implementation of the Standard on Transparency and Exchange of Information on Request (EOIR), recommended that Liechtenstein should “further strengthen” measures so that that beneficial ownership information is available in respect of “all relevant entities and arrangements as required under the standard.”
 
The OECD report made no reference to the cybersecurity angle. It said that under new legislation, the Fiscal Authority (Liechtenstein’s competent authority) has access to the beneficial ownership register. The Financial Intelligence Unit, the Financial Market Authority, the Prosecutors Office, the Princely Court, the National Police, AML-obliged persons and the Liechtenstein Bar Association (as a supervisory authority) also have access to the register. Liechtenstein has taken “comprehensive actions to address the recommendation and is no longer required to report,” the OECD said, noting that a “previous gap” in beneficial ownership information had been closed by new legislation. 

The Liechtenstein cybersecurity case is the latest in a series of data leaks, including the Panama Papers and the Paradise papers, both of which led to HMRC opening probes into UK taxpayers.

When governments enter automatic exchange of information agreements with the ostensible purpose of foiling tax evaders and illicit financial flows, such incidents raise questions about what happens if criminals and other hostile actors break into the data "vaults," and where the liability rests? Some countries, such as those in the European Union are under the General Data Protection Regulation (GDPR) powers that went into effect in 2018 (the UK remains under this, even after leaving the EU). Certain states in the US, such as California, have a version of GDPR, while the US as a whole so far doesn’t have this at a federal level. (This recent controversy about New York City Mayor Zohran Mamdani's database on "pied à terre" homes also raises questions about BO information.) Regulations elsewhere in the world are patchy. 

The editor of this news service examined a list of major breaches and attacks on government data sources over the past six months. Here are examples. Some of the cases are still live and haven’t been fully resolved.

UK
The UK Companies House WebFiling case, which happened in March. A vulnerability in CH’s WebFiling service, traced to an October 2025 system update, let logged-in users view, and, under some conditions potentially amend another company's dashboard. This enabled changes to be made to data such as directors' home addresses, dates of birth and emails. The vulnerability was discovered between 12 and 13 March by a corporate services researcher. Companies House took WebFiling offline on 13 March and restored it on 16 March. CH said no paswords, identity-verification data or filed documents had been altered. 

The Netherlands
On 19 March, the Ministry's ICT security team detected unauthorised access to systems. A tip-off was received by a third party who alerted the Ministry to suspicious activity. Affected systems, including a Treasury banking portal, were deliberately taken offline on 23 March to stop data being exfiltrated.

Tax collection, customs and income-linked subsidy systems that handled more than 9.5 million income tax returns a year were not affected, reports said. The breach was reported to the Dutch Data Protection Authority over possible exposure of employee data. No group has claimed responsibility. 

The Netherlands and EU
The European Commission, the Dutch Data Protection Authority and Judicial Council were hacked. Work-related names, emails and phone numbers were accessed in the Dutch incident, while the Commission contained its breach within nine hours. 

Sweden
The cybercrime group ByteToBreach reportedly stole Swedish government data from its E-Gov platform. 

Spain
Check Point Research identified a malicious email campaign impersonating the Spanish tax authority, Agencia Tributaria (AEAT), with a spoofed email sent to a Spanish industrial company, carrying a trojan-downloader attachment, reports said. This did not breach AEAT's own systems, but it was part of a wider range of attacks.  

General
Comparitech recorded 187 ransomware attacks on government agencies worldwide in the first half of this year, rising 13 per cent from the second half of 2025. Several of these attacks hit agencies that hold tax and business-registration data at the state/municipal level.

Hong Kong
Data on Asia breaches or attacks where governments acknowledge an issue are less common, or not so widely reported in the media. Hong Kong regulators (Hong Kong Monetary Authority and Securities and Futures Commission) issued circulars in late May/early June calling for enhanced cybersecurity measures against AI-enabled cyberattacks.

Singapore
The Monetary Authority of Singapore has launched a task force to tackle AI-driven attacks and strengthen cybersecurity. 

Register for WealthBriefing today

Gain access to regular and exclusive research on the global wealth management sector along with the opportunity to attend industry events such as exclusive invites to Breakfast Briefings and Summits in the major wealth management centres and industry leading awards programmes