Cyberattack on Liechtenstein: 31,000 Records Stolen from Registry

Step by step
How the attack unfolded
Click a phase for details – or let the animation play through.
PHASE 1/4 · Initial Access

Unknown attackers gained access to a state financial register of Liechtenstein.

  • Affected: Register of ultimate beneficial owners (UBO register)
  • Entry vector and exploited vulnerability unknown
  • Perpetrators remain unidentified
PHASE 2/4 · Collection

The attackers accessed the full beneficial-owner register data.

  • Names and details of 31,000 individuals affected
  • Data of owners, foundations and trust structures
  • Victims likely from DACH region and internationally
PHASE 3/4 · Exfiltration

The stolen personal data ended up in the attackers' hands.

  • Data of 31,000 individuals stolen
  • Possible resale on underground marketplaces suspected
  • No evidence of ransomware encryption in the material
PHASE 4/4 · Impact

The incident breaches the confidentiality of sensitive financial structures and creates follow-on risks.

  • No ransom demand made — unusual
  • Government convened a crisis team on 3 August 2026
  • Crisis team led by head of government Brigitte Haas
  • Risk of targeted fraud and extortion against victims
Short & clear answers
Frequently asked questions about this incident
Am I affected by the Liechtenstein data breach?
The breach affects 31,000 people listed in Liechtenstein's register of beneficial owners. This includes owners and beneficial owners of companies, foundations and trusts in Liechtenstein – including people from Germany, Austria and Switzerland. If you are connected to such a structure in Liechtenstein, you should take the incident seriously.
How can I check whether my data was stolen?
No official checking tool for individuals is currently known. Check whether you are registered as a beneficial owner of a Liechtenstein company, foundation or trust, and ask your trustee, law firm or asset manager. In a data breach of this scale, affected individuals must generally be notified individually – so watch for official communications from the authorities.
What should I do now to protect myself?
Be especially vigilant against targeted fraud such as spear phishing – personalised emails or calls pretending to be your bank, trustee or a public authority. Never carry out sensitive actions like transfers or password changes on request or under time pressure, and when in doubt call back using a known official number. Also contact your trustee or legal advisor to clarify which of your data may be affected and what further steps to take.
What data was stolen in the attack?
The stolen data comes from the register of beneficial owners, which contains the names and details of the individuals behind companies, foundations and trust structures. These are the actual owners or beneficiaries (Ultimate Beneficial Owners, UBOs), even when legal entities are formally interposed. No details are available on the exact technical course of the attack.
Was a ransom demanded and who is behind it?
So far no ransom has been demanded, which is unusual for cyberattacks. The perpetrators are also still unknown. Possible explanations include pure interest in the data (for example for corporate espionage or fraud) or resale on underground markets – but this remains speculation.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.