Offshore
Liechtenstein Beneficial Ownership Register Hit By Cyber Attack
.jpg)
After copies of data relating to 31,000 legal entities were unlawfully taken, the register has been temporarily closed for external users. The government said there were no signs that data had been modified or deleted.
The government in Liechtenstein is racing to establish the extent
of damage caused by an attack on beneficial ownership data held
in the tiny European state. Copies of data covering around 31,000
legal entities have been taken.
“The Register of Beneficial Owners (VwbP) has been the target of
a cyberattack,” the government said yesterday. The administration
has formed a crisis unit.
“Copies of data relating to around 31,000 legal entities were
unlawfully exfiltrated,” it said in a statement. “As a result of
the incident, the register is not available to external users via
the llv.li website for the time
being. According to the current state of knowledge, there are no
indications that data in the system was modified or deleted.”
The attack is an example of how cross-border financial centres
that are used by wealthy individuals, companies and other
institutions to hold wealth are in the cybersecurity firing
line.
The register, aka VwbP, is “maintained for the purpose of
preventing money laundering and terrorist financing,” the
government statement said. The register holds data on the
beneficial owners of legal entities that include companies,
foundations, and trusts.
The government in Vaduz said that based in preliminary findings,
unknown perpetrators gained unlawful access to the VwbP by
digital means during the night of 29/30 July 2026. During 30
July, “irregularities were noticed at the Office of Justice.”
“The Office of Information Technology was subsequently contacted
to analyse the situation. Based on the initial suspicion, the
Office of Information Technology immediately implemented measures
to secure the data and took the affected system offline,” the
government statement said.
The government said it has started checks into what had happened.
On Friday 31 July, the government said it was told that a
potentially successful attack on the VwbP had taken place. On the
afternoon of 1 August 2026, the first confirmed results of the
preliminary investigations were transmitted to the
government.
The government convened a crisis unit on Saturday evening, which
began its work immediately, and formally confirmed it the
following day. Prime Minister Brigitte Haas and Minister of
Justice Emanuel Schädler are heading the unit.
The Act on the Register of the Beneficial Owners of Legal
Entities (VwbPG) entered into force in 2021, implementing the
requirements of the 5th EU Anti-Money Laundering Directive.
Registers in focus
“Under the digital trust model taking shape in Europe, the
registry stops being a noticeboard we query and becomes the
authentic source, a body that can sign a statement about who owns
and controls a company, which thousands of institutions then rely
on,” Steve Lamb, CEO of Kyckr, a firm providing live access
official company registers, said in an emailed comment to
WealthBriefing. “Once that happens, the security of the
source underpins the security of the whole chain, and an
authentic source that can be compromised doesn’t inspire much
confidence. The debate can’t only be about standards, schemas and
interoperability. Registries are becoming critical financial
infrastructure, and they should be resourced like it.”
The digital trust model Lamb cited is called the European
Business Wallet, eIDAS 2.0.
The government statement noted that the attack on the VwbP
constitutes a personal data breach under General Data Protection
Regulation (GDPR) rules.
(Editor’s comment: These are early days, so jumping to
conclusions is unwise. This news service has regularly, as
here, commented on the tensions between providing registers
of beneficial ownership in the name of transparency, and the
threat to legitimate privacy. Cyber attacks and the advent of AI
have raised the stakes.)