Liechtenstein's Register of Beneficial Owners suffered a cyberattack on the night of July 30, 2026, resulting in unauthorized access to data copies linked to approximately 31,000 legal entities. The Office of Justice detected irregularities later that day and immediately contacted the Office of Information Technology to investigate. The affected system was secured and removed from external access while authorities launched a detailed technical investigation.
The Register of Beneficial Owners (VwbP) stores information about the beneficial owners of companies, foundations, and trusts. Established under the Law on the Register of Beneficial Owners of Legal Entities (VwbPG) in 2021, the register implements requirements from the 5th EU Anti-Money Laundering Directive. Its primary purpose is to support money laundering prevention and combat terrorist financing by maintaining records of individuals who ultimately control or benefit from legal entities.
Investigators confirmed on July 31 that the breach may have been successful, with preliminary findings submitted on August 1 confirming that attackers unlawfully accessed the directory and stole data copies. Based on current findings, there is no indication that any information stored in the system was altered or deleted during the incident. The register remains temporarily offline for external users through the LLV.li website while the investigation continues.
The government established a crisis team on August 1, formally confirmed the following day and led by Prime Minister Brigitte Haas and Justice Minister Emanuel Schädler. The team's priorities include conducting a full investigation, informing affected individuals, and implementing appropriate countermeasures. Authorities classified the incident as a data breach involving personal information under Article 33 of the General Data Protection Regulation (GDPR).
The crisis team is working to notify affected individuals in accordance with Article 34 GDPR as quickly as possible. A central information point is being established to respond to questions from those impacted by the breach. Authorities continue investigating how the unauthorized access occurred and whether additional security measures will be required to strengthen the register's defenses. Organizations and individuals whose data was stored in the register should monitor for potential misuse of their information and watch for official notifications from Liechtenstein authorities.
Source: https://thecyberexpress.com/beneficial-owners-register-breach/


