Print this article

ANALYSIS: Liechtenstein’s Cybersecurity Attack Part Of Global Trend

Editorial Staff

5 August 2026

As reported here, the Liechtenstein government has disclosed that a register of beneficial ownership with 31,000 legal entities was hit in a cybersecurity attack.  

The episode shows how government-run registers, databases and other information sources can be targeted. This raises questions on whether the drive for transparency on beneficial ownership data can clash with security of that information. 

Revenue-gathering authorities in countries that have engaged in tax disclosure pacts with Liechtenstein, such as the UK will monitor the situation. 

“It is not clear how and when any information obtained from this latest data leak will be used. However, with Liechtenstein being home to many low-tax trusts, one thing we can be sure of is that HMRC will be watching developments closely," Alistair Culverwell, partner and head of tax dispute resolution, Forvis Mazars, said in an emailed statement to this news service. 

The attack is a blow to Liechtenstein, a jurisdiction that received a “Largely Compliant” rating from the OECD in a report in June this year. The Paris-headquartered body, in its Enhanced Monitoring Report on the Implementation of the Standard on Transparency and Exchange of Information on Request (EOIR), recommended that Liechtenstein should “further strengthen” measures so that that beneficial ownership information is available in respect of “all relevant entities and arrangements as required under the standard.”
 
The OECD report made no reference to the cybersecurity angle. It said that under new legislation, the Fiscal Authority (Liechtenstein’s competent authority) has access to the beneficial ownership register. The Financial Intelligence Unit, the Financial Market Authority, the Prosecutors Office, the Princely Court, the National Police, AML-obliged persons and the Liechtenstein Bar Association (as a supervisory authority) also have access to the register. Liechtenstein has taken “comprehensive actions to address the recommendation and is no longer required to report,” the OECD said, noting that a “previous gap” in beneficial ownership information had been closed by new legislation. 

Besides cybersecurity attacks are data leaks including the Panama Papers and the Paradise papers episodes.

When governments enter automatic exchange of information agreements with the ostensible purpose of foiling tax evaders and illicit financial flows, cybersecurity attacks raise questions about what happens if criminals and other hostile actors break into the data "vaults". Some countries, such as European Union member states, are under the General Data Protection Regulation (GDPR) powers that went into effect in 2018 (the UK remains under this, even after leaving the EU). Certain states in the US, such as California, have a version of GDPR, while the US as a whole so far doesn’t have this at a federal level. (This recent controversy about New York City Mayor Zohran Mamdani's database on "pied à terre" homes also raises questions about BO information.) Regulations elsewhere in the world are patchy. 

Liechtenstein has already acknowledged the latest attack is a personal data breach under GDPR rules.

The editor of this news service examined a list of major breaches and attacks on government data sources over the past six months. Here are examples. Some of the cases are still live and haven’t been fully resolved.

UK
The UK Companies House WebFiling case, which happened in March. A vulnerability in CH’s WebFiling service, traced to an October 2025 system update, let logged-in users view, and, under some conditions potentially amend another company's dashboard. This enabled changes to be made to data such as directors' home addresses, dates of birth and emails. The vulnerability was discovered between 12 and 13 March by a corporate services researcher. Companies House took WebFiling offline on 13 March and restored it on 16 March. CH said no paswords, identity-verification data or filed documents had been altered. 

The Netherlands
On 19 March, the Ministry's ICT security team detected unauthorised access to systems. A tip-off was received by a third party who alerted the Ministry to suspicious activity. Affected systems, including a Treasury banking portal, were deliberately taken offline on 23 March to stop data being exfiltrated.

Tax collection, customs and income-linked subsidy systems that handled more than 9.5 million income tax returns a year were not affected, reports said. The breach was reported to the Dutch Data Protection Authority over possible exposure of employee data. No group has claimed responsibility. 

The Netherlands and EU
The European Commission, the Dutch Data Protection Authority and Judicial Council were hacked. Work-related names, emails and phone numbers were accessed in the Dutch incident, while the Commission contained its breach within nine hours. 

Sweden
The cybercrime group ByteToBreach reportedly stole Swedish government data from its E-Gov platform. 

Spain
Check Point Research identified a malicious email campaign impersonating the Spanish tax authority, Agencia Tributaria (AEAT), with a spoofed email sent to a Spanish industrial company, carrying a trojan-downloader attachment, reports said. This did not breach AEAT's own systems, but it was part of a wider range of attacks.  

General
Comparitech recorded 187 ransomware attacks on government agencies worldwide in the first half of this year, rising 13 per cent from the second half of 2025. Several of these attacks hit agencies that hold tax and business-registration data at the state/municipal level.