Published on 3 August 2026
On the night of 30–31 July 2026, unknown attackers gained access to the data of around 31,000 legal entities – companies, foundations and trusts. The target was Liechtenstein's register of beneficial owners, known as the VwbP. What was stolen was not just company names, but identities, addresses and detailed ownership information – precisely the kind of data that is supposed to be strictly protected. Who stands behind a foundation or company, who controls it and where these people can be reached: all of this is now potentially in the wrong hands.
For many owners of small and medium-sized enterprises with ties to Liechtenstein, this is more than a distant news item. Anyone who holds a Liechtenstein structure or is connected to one in a business capacity could be directly affected. In this article we explain what happened, why this register exists in the first place, who is at risk – and what you should do right now.
According to the information available so far, the perpetrators broke into the register of beneficial owners (VwbP) during the night of 31 July 2026. The term "beneficial owner" – often referred to in technical jargon as the Ultimate Beneficial Owner (UBO) – means the natural person who ultimately stands behind a company, foundation or trust and controls it or benefits from it.
The attackers did not simply take a look at the database; they copied the records out of it – the technical term for this process is exfiltration, meaning the deliberate extraction of data from a system. According to the report, around 31,000 legal entities are affected, involving the following data categories:
In response, the responsible Office of Justice took the register offline. In addition, a crisis unit under Prime Minister Brigitte Haas was set up to deal with the incident.
Remarkable – and, from a security analysis perspective, unusual: so far no perpetrator has come forward, and no ransom has been demanded. This sets the attack apart from classic ransomware cases, in which criminals encrypt data and demand money for its release. When no ransom is involved, it often suggests that the data itself is the sole objective – whether for resale, targeted analysis, or intelligence interest. However, no firm conclusions about the motive are yet available.
The abbreviation AML stands for Anti-Money-Laundering. Registers of beneficial owners were introduced in Europe to create transparency about who actually stands behind companies and complex legal structures. Foundations and trusts in particular lend themselves to concealing the true owners. Such registers are meant to enable authorities, banks and – in certain cases – authorised third parties to break through this concealment.
The paradox of this incident: a register that is actually meant to make transparency harder to evade for criminals has now itself become a data source for potential criminals. The central bundling of sensitive ownership data in one place makes such registers an attractive target – anyone who breaks in gains, in one fell swoop, a high-value overall picture of entire corporate landscapes.
Another piece of context is timely and sensitive: according to the report, the attack took place 24 days after the implementation deadline of the so-called AMLD6 had passed. AMLD6 is the sixth EU Anti-Money Laundering Directive (Sixth Anti-Money Laundering Directive), which tightens anti-money-laundering rules across Europe. The fact that a central register was compromised just after this regulatory milestone raises questions about the security of such systems – beyond Liechtenstein too.
Affected, in principle, are the roughly 31,000 legal entities whose data is held in the VwbP register. Specifically, this means:
Even if your company has its headquarters in Germany: if you work with Liechtenstein structures – for example through a shareholding, a foundation, a trust or a subsidiary based there – your personal or company information may be contained in the stolen data.
No concrete checking tools or official "am I affected?" enquiry services have been published so far. Nevertheless, you can take the following steps to assess whether you are affected:
Even though no ransom was demanded, this does not mean there is no danger – quite the opposite. When ownership data circulates freely, the risk of targeted attacks increases. We recommend the following immediate measures:
Even though Liechtenstein is not an EU member state, it belongs to the European Economic Area and applies the General Data Protection Regulation (GDPR). The stolen information is, at least in part, personal data – namely the names and addresses of the beneficial owners. This means the incident is fundamentally to be classified as a data breach within the meaning of the GDPR.
For companies, this means: if personal data for which you are responsible has been caught up in the data leak, reporting and notification obligations may apply. In certain cases, the GDPR provides for a report to the competent supervisory authority as well as notification of the individuals affected. Whether and to what extent this applies to you depends on the individual case – here it pays to coordinate early with a data protection adviser.
We rate the severity of this incident as high. Several factors support this:
The good news: the register was taken offline immediately by the Office of Justice, and a crisis unit was set up at the highest level of government. This shows that the incident is being taken seriously and is being actively addressed.
The attack on Liechtenstein's register of beneficial owners is a wake-up call – especially for small and medium-sized enterprises that use cross-border structures. It shows that even state-run registers, which are actually supposed to create security and transparency, can become targets. And it makes one thing clear: data protection does not end at your own firewall, but also depends on how well the systems of third parties – to whom you transmit your data – are protected.
If you have dealings with Liechtenstein structures, do not wait and see. Clarify whether you are affected, talk to your trustee and your legal advisers, and sharpen your team's awareness of phishing and CEO fraud. Because where ownership data circulates, experience shows that targeted fraud attempts follow. Those who are prepared now make themselves a far less attractive target.
We will continue to follow the development of this incident and will update this article as soon as official bodies publish further information.
Source: TechTimes, "Liechtenstein Data Breach: Attackers Hack AML Registry, Exposing EU Security Flaw", published on 3 August 2026.