Data Breach in Liechtenstein: 31,000 Transparency Register Entries Copied

Step by step
How the attack unfolded
Click a phase for details – or let the animation play through.
PHASE 1/4 · Initial Access

Unknown actors gained unauthorized digital access to the VwbP register on the night of 30 July 2026, likely via a vulnerability at an external IT supplier.

T1190 – Exploit Public-Facing Application T1078 – Valid Accounts
  • Target system: Register of beneficial owners (VwbP), Liechtenstein Office of Justice
  • Multiple indicators point to a vulnerability at an external IT supplier
  • Possible entry vectors: compromised credentials, API vulnerability or a web-application flaw
  • On 4 August forensics identified a possible entry point
PHASE 2/4 · Collection

The attackers accessed the entire dataset of the central register instead of retrieving individual records.

T1213 – Data from Information Repositories T1530 – Data from Cloud Storage
  • Affected: around 31,000 legal-entity records (more than the ~23,000 active entries)
  • Historical and deleted entries were also present in the system
  • Captured fields: first name, surname, date of birth, nationality, country of residence
  • Mass access points to exploitation of a technical vulnerability
PHASE 3/4 · Exfiltration

The complete dataset of around 31,000 beneficial owners was copied and exfiltrated.

T1567 – Exfiltration Over Web Service
  • Pure data exfiltration without encryption, manipulation or deletion
  • A single successful breach stole the data of all clients simultaneously
  • Volume equals roughly 75% of Liechtenstein's population (~41,000)
  • Also affects individuals and companies from the DACH region
PHASE 4/4 · Impact

The incident was discovered, the system taken offline and a crisis team set up; notably, no ransom demand was made.

  • Discovered on 30 July during a routine check by an employee
  • Precautionary shutdowns: eMWST portal, 'Lides' platform, Central Account Register, Intax
  • Crisis team led by PM Haas and Justice Minister Schädler; criminal complaint filed 2 August
  • No ransom demand, no darknet publication – atypical for ordinary cybercriminals
Short & clear answers
Frequently asked questions about this incident
Am I affected by the Liechtenstein VwbP data breach?
The breach affects the beneficial owners of around 31,000 Liechtenstein legal entities (companies, foundations, trusts). If your business or its beneficial owners hold or held such a structure in Liechtenstein, you are very likely affected. Since the 31,000 records exceed the number of active entities, historical or already-deleted records may also be affected.
Which of my data was stolen?
The copied data includes name, first name, date of birth, nationality, and country of residence of the beneficial owners. According to the Office of Justice, no addresses, phone numbers, financial, or banking data were affected. The Liechtenstein Bankers Association confirmed that no banks or bank-specific customer data were involved.
What exactly should I do now?
Be especially alert to phishing: ignore links and attachments in emails claiming to come from the Office of Justice, trustees, or the crisis team, and verify senders through official channels (regierung.li). Contact your trustee or lawyer in Liechtenstein regarding your registration status and involve your data protection officer. Secure sensitive accounts with multi-factor authentication.
How can I check if I'm affected, and who can I contact?
Check whether your company or its beneficial owners are or were registered in Liechtenstein structures, and ask your trustee, notary, or lawyer about your VwbP registration status. Watch for official notifications from the Liechtenstein authorities. Inquiries can be sent directly to the dedicated contact point at vwbpfragen@llv.li.
How dangerous is the attack if no banking data was affected?
Even without financial data, the stolen identity information is valuable for targeted social engineering, phishing, vishing (phone fraud), and identity theft. Notably, no ransom demand has been made and the data has not yet appeared on the dark web—a pattern atypical of ordinary cybercriminals. Therefore, raise awareness among all beneficial owners about heightened fraud risks.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.