Published on 5 August 2026
Around 31,000 records of beneficial owners from Liechtenstein may now be in the wrong hands. During the night of 30 July 2026, unknown attackers compromised the central register of beneficial owners (Verzeichnis wirtschaftlich berechtigter Personen, VwbP) of the Principality of Liechtenstein and copied the entire dataset. Affected are not only Liechtenstein legal entities, but also numerous companies and individuals from Germany, Austria and Switzerland who maintain companies, foundations or trust structures in Liechtenstein. If your company owns or once owned such a structure, you should read this article to the end – and then act.
The VwbP is the central state register that, since 2021, has recorded the beneficial owners behind companies, foundations and trusts. It was introduced by the Office of Justice on the basis of the 5th EU Anti-Money Laundering Directive (AMLD5) – an EU requirement intended to prevent criminals from hiding their true identity behind corporate structures. It is precisely this register that has now become the target of a deliberate attack.
During the night of 30 July 2026, unknown parties gained unlawful digital access to the system and copied the records of around 31,000 legal entities. According to the Office of Justice, the following personal data of the beneficial owners were affected:
Explicitly not affected, according to official statements, are addresses, telephone numbers, financial or bank data. Martin Alge, head of the Office of Justice, confirmed:
“Personal data of the beneficial owners have been affected. The affected records comprise the surname, first name, date of birth and nationality of the recorded individuals.”
Notable: the 31,000 copied records exceed the number of currently active legal entities (estimated at around 23,000). This suggests that historical or already deleted entries were also contained in the system – so the attack could also affect individuals and structures that have long since ceased to be active.
The incident was discovered on 30 July 2026 by an attentive employee of the Office of Justice, who noticed irregularities during a routine check. The Office of Information Technology immediately secured the data and took the system offline that same day. On 31 July the government was informed, on 1 August the first confirmed results were available, and on the evening of that same day the government convened a crisis unit. This was formally confirmed on 2 August under the leadership of Prime Minister Brigitte Haas and Justice Minister Emanuel Schädler; on the same day the public announcement was made and a criminal complaint filed against persons unknown.
On 3 August the crisis unit confirmed a deliberate attack of a high technical level. On 4 August the forensic investigation identified a possible point of entry. The investigation is being carried out in cooperation with European authorities.
The exact attack path has not yet been conclusively confirmed. Fabian Schmid, head of the Office of Information Technology, explained on 4 August:
“According to current knowledge, this was a deliberate attack of a high technical level against a highly complex security structure.”
Several indications point to a vulnerability at an external IT supplier. As a precaution, two further portals from the same provider were taken offline: the eMWST portal and the “Lides” platform – even though no data leakage was detected there. Later, as a precaution, the Central Register of Accounts and the Intax tax processing system were also taken offline.
Since it was not individual records but the entire dataset that was copied all at once, experts assume the exploitation of a technical vulnerability that enabled mass access – conceivable causes include compromised access credentials, an API vulnerability (a programming interface through which systems exchange data automatically) or a security flaw in the web application.
The attack pattern is striking: pure data exfiltration (data leakage) without encryption, without manipulation, without deletion. This is untypical of ordinary cybercriminals. The journalist Gregor Meier of Landesspiegel.li sums it up:
“The most striking finding is an absence. There is no ransom demand. The data have so far not surfaced on the dark web. Nothing was encrypted, nothing deleted, nothing altered. That is precisely not how ordinary cybercriminals behave.”
TechTimes analyst Kyle Belmonte points to the fundamental structural problem: the regulatory mandate to break down financial secrecy created exactly the centralised, high-value database that is most attractive to attackers. A successful breach steals not the data of one customer – but of all customers at once.
Affected are the beneficial owners of around 31,000 Liechtenstein legal entities. Since Liechtenstein is an international financial centre, this most likely also affects many individuals and companies from the DACH region (Germany, Austria and Switzerland) who hold companies, foundations or trust structures there.
To put the scale into perspective: according to the IMF, the country manages around 773 billion Swiss francs in financial assets – roughly one hundred times its own gross domestic product. The 31,000 records correspond to around 75 percent of Liechtenstein’s total population (approx. 41,000).
The Liechtenstein Bankers Association made clear: “No banks or bank-specific customer data are affected.” The matter therefore concerns exclusively the identity data of the beneficial owners from the register – not account balances or bank details.
The government of Liechtenstein has officially classified the incident as a personal data breach under Art. 33 GDPR and informed the Liechtenstein Data Protection Authority. Its press release states:
“The crisis unit is working at full speed to ensure that, in accordance with Art. 34 GDPR, the affected persons are informed of the breach of the protection of their data as quickly as possible.”
For German SMEs with Liechtenstein structures, this may give rise to their own responsibility:
To put the scale into perspective: in Germany in 2025, a total of 249 GDPR fines amounting to nearly €47 million were imposed, with the highest single fine standing at €45 million (against Vodafone). Across Europe, GDPR fines in 2025 amounted to almost €1.2 billion.
The severity is to be classified as high. Even though no ransom demand and no publication on the dark web are known so far, this is no reason to sound the all-clear – quite the opposite. The combination of identity data and the link to a specific legal entity enables highly credible, personalised phishing attacks, for example in the name of trustees, banks or the Office of Justice. Experience shows that the second wave of attacks sets in precisely in the days after a data breach becomes known.
A lawyer specialising in IT law, quoted on ad-hoc-news.de, warns:
“The stolen data could be used for long-term risks such as identity abuse or targeted phishing attempts – the data could allow conclusions to be drawn about financial circumstances.”
The absence of a ransom demand points to a strategically acting player who is processing the data for targeted, long-term use – whether for later extortion of individual affected persons, for sale, or for intelligence purposes. The incident joins a series of similar attacks: in France, the central customer register FICOBA, with 1.2 million records, was hacked in February 2026, and in Lithuania a state register system with around 600,000 records was hacked in May 2026.
The attack on the Liechtenstein transparency register reveals an uncomfortable truth: centralised registers created to combat money laundering have themselves become high-value targets. For companies and individuals with Liechtenstein structures, this now means above all one thing – heightened vigilance. Expect particularly well-crafted phishing attempts in the coming weeks, verify every contact attempt through official channels, and clarify your registration status with your trustee. In addition, check whether you have your own GDPR reporting obligations, and document all measures.
The VwbP remains offline for now, no patch yet exists (as of 4 August 2026), and the forensic investigations are ongoing. Anyone affected should not wait for the official notification, but act proactively – because in the fight against identity abuse and social engineering, every day of lead time counts.