Liechtenstein authorities are investigating a cyberattack that compromised the country's Register of Beneficial Owners (VwbP), resulting in the unauthorized exfiltration of data related to approximately 31,000 legal entities. The breach occurred during the night of July 29-30, 2026, when unknown attackers gained digital access to the system. The Office of Justice detected irregularities on July 30 and immediately took the register offline, suspending external access through the llv.li website while investigations continue.
The VwbP maintains records of beneficial owners for companies, foundations, trusts, and other legal entities as part of Liechtenstein's compliance with anti-money laundering and counter-terrorist financing requirements. The register was established under the Register of Beneficial Owners Act (VwbPG), which came into force in 2021 to implement the 5th EU Anti-Money Laundering Directive. The breach has been classified as a personal data breach under the General Data Protection Regulation (GDPR).
According to government statements, copies of data were unlawfully accessed and removed from the system. However, preliminary investigations found no evidence that records were modified or deleted within the register itself. The Office of Information Technology secured the affected systems immediately after detection, and authorities delivered preliminary investigation results on August 1, 2026. The government established a crisis unit led by Prime Minister Brigitte Haas and Minister of Justice Emanuel Schädler to coordinate the response.
The incident highlights significant security risks facing international financial centers that manage sensitive ownership information for wealthy individuals, businesses, and institutions. Steve Lamb, CEO of Kyckr, noted that registries are becoming critical infrastructure within Europe's digital trust framework, particularly as systems like the European Business Wallet and eIDAS 2.0 rely on registries as authentic sources for ownership verification. He emphasized that as these systems become foundational to the financial ecosystem, they require corresponding security resources and protections.
Authorities continue investigating to determine the full scope and impact of the breach. Organizations and individuals whose beneficial ownership information is recorded in the VwbP should prepare for potential exposure of sensitive corporate structure and ownership data. While the register remains offline to external users, officials have not provided a timeline for restoration of services or details about potential notification procedures for affected entities.
Source: https://thecyberexpress.com/liechtenstein-cyberattack-vwbp/


