Data Breach in Liechtenstein: 31,000 Firms and Foundations Hit

Step by step
How the attack unfolded
Click a phase for details – or let the animation play through.
PHASE 1/4 · Initial Access

Unknown attackers breached the publicly accessible register of beneficial owners (VwbP) during the night of July 31, 2026.

T1190 – Exploit Public-Facing Application
  • Target system: Liechtenstein VwbP register (UBO database)
  • Time of incident: night of July 30 to 31, 2026
  • Attack occurred 24 days after the AMLD6 transposition deadline
  • Specific intrusion vector not yet publicly known
PHASE 2/4 · Collection

The attackers accessed the centrally bundled, highly sensitive owner data of around 31,000 legal entities.

T1213 – Data from Information Repositories
  • Around 31,000 affected legal entities (companies, foundations, trusts)
  • Data categories: identities of beneficial owners, addresses, ownership details
  • Central bundling of sensitive data made the register an attractive target
PHASE 3/4 · Exfiltration

The attackers deliberately copied the datasets out of the system (exfiltration).

T1030 – Data Transfer Size Limits T1041 – Exfiltration Over C2 Channel
  • Not merely read access – datasets were copied out
  • Stolen: identities, addresses and ownership details of entire corporate landscapes
  • Attackers gained a high-value overall picture of the UBO structures
PHASE 4/4 · Impact

The Justice Office took the register offline and set up a crisis unit; the motive remains unclear.

  • Register was taken offline in response
  • Crisis unit established under Prime Minister Brigitte Haas
  • No claim of responsibility, no ransom demand – atypical for ransomware
  • Possible motives: resale, targeted analysis or intelligence interest
Short & clear answers
Frequently asked questions about this incident
Am I affected by the data breach at Liechtenstein's UBO register?
Around 31,000 legal entities whose data is stored in Liechtenstein's beneficial ownership register (VwbP) are affected. If your company, foundation, or a trust you use is registered in Liechtenstein – or you are connected to such a structure through a shareholding – your data may be included. Companies headquartered in Germany can also be affected if they work with Liechtenstein structures.
What data was stolen in the attack?
The attackers obtained the identities of beneficial owners, their addresses, and detailed ownership information about companies, foundations, and trusts. This goes beyond mere company names and includes precisely the sensitive data that was supposed to be strictly protected. The attackers copied these records out of the system in a process known as exfiltration.
How can I check whether I am affected?
No official checking tools or breach-lookup services have been published so far. First clarify internally or with your trustee or legal advisor whether your structure is registered in the VwbP register. Your local trustee or management company is the first point of contact, and you should keep an eye on official announcements from Liechtenstein's Office of Justice.
What exactly should I do now?
Expect targeted fraud attempts such as spear-phishing and CEO fraud, and raise your team's awareness – especially by setting clear payment approval processes that cannot be confirmed by email alone. Inform affected individuals, document the incident for your compliance records, and seek legal advice regarding your reporting and notification obligations.
Was a ransom demanded and how dangerous is this incident?
So far no perpetrator has claimed responsibility and no ransom has been demanded, which sets this attack apart from typical ransomware cases. This does not mean there is no danger – quite the opposite: when no ransom is involved, the goal is often the data itself, for example for resale or targeted exploitation. Freely circulating ownership data increases the risk of targeted attacks.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.