Cyberattack on Liechtenstein’s Beneficial Owners Register Exposes Data of 31,000 Legal Entities
On July 30, 2026, unknown attackers breached Liechtenstein’s Register of Beneficial Owners (VwbP), accessing data copies linked to approximately 31,000 legal entities, including companies, foundations, and trusts. The intrusion was detected later the same day by the Office of Justice, prompting an immediate response from the Office of Information Technology.
Authorities secured the affected system by removing it from external access and taking the register offline for external users via the LLV.li website. While initial findings indicate no evidence of data alteration or deletion, the breach involved unauthorized access to sensitive information identifying beneficial owners, mandated under the 2021 Law on the Register of Beneficial Owners (VwbPG) to comply with the EU’s 5th Anti-Money Laundering Directive.
A government-led crisis team, led by Prime Minister Brigitte Haas and Justice Minister Emanuel Schädler, was convened on August 1, 2026, and formally confirmed the following day. The team’s priorities include a full investigation, notifying affected individuals under Article 34 of the GDPR, and implementing countermeasures. A central information point has been established to address inquiries from impacted parties.
The incident qualifies as a GDPR data breach, triggering a formal notification process. Authorities continue to assess how the breach occurred and whether additional security measures are needed to prevent future incidents.
Source: https://thecyberexpress.com/beneficial-owners-register-breach/
Register of Beneficial Owners TPRM report: https://www.rankiteo.com/company/central-rbo
"id": "cen1785760004",
"linkid": "central-rbo",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '31,000 legal entities '
'(companies, foundations, and '
'trusts)',
'industry': 'Government',
'location': 'Liechtenstein',
'name': 'Liechtenstein’s Register of Beneficial Owners '
'(VwbP)',
'type': 'Government Register'}],
'customer_advisories': 'Central information point established for affected '
'parties',
'data_breach': {'number_of_records_exposed': '31,000',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Beneficial ownership '
'information'},
'date_detected': '2026-07-30',
'date_publicly_disclosed': '2026-08-01',
'description': 'On July 30, 2026, unknown attackers breached Liechtenstein’s '
'Register of Beneficial Owners (VwbP), accessing data copies '
'linked to approximately 31,000 legal entities, including '
'companies, foundations, and trusts. The intrusion was '
'detected later the same day by the Office of Justice, '
'prompting an immediate response from the Office of '
'Information Technology. Authorities secured the affected '
'system by removing it from external access and taking the '
'register offline for external users via the LLV.li website. '
'While initial findings indicate no evidence of data '
'alteration or deletion, the breach involved unauthorized '
'access to sensitive information identifying beneficial '
'owners, mandated under the 2021 Law on the Register of '
'Beneficial Owners (VwbPG) to comply with the EU’s 5th '
'Anti-Money Laundering Directive.',
'impact': {'data_compromised': 'Sensitive information identifying beneficial '
'owners',
'identity_theft_risk': 'High',
'legal_liabilities': 'Potential GDPR violations',
'operational_impact': 'Register taken offline for external users',
'systems_affected': 'Register of Beneficial Owners (VwbP)'},
'investigation_status': 'Ongoing',
'references': [{'source': 'Government of Liechtenstein'}],
'regulatory_compliance': {'regulations_violated': ['GDPR',
'EU’s 5th Anti-Money '
'Laundering Directive'],
'regulatory_notifications': 'Formal notification '
'under Article 34 of '
'the GDPR'},
'response': {'communication_strategy': 'Central information point established '
'for inquiries',
'containment_measures': 'System removed from external access, '
'register taken offline',
'incident_response_plan_activated': 'Yes'},
'stakeholder_advisories': 'Government-led crisis team convened, including '
'Prime Minister Brigitte Haas and Justice Minister '
'Emanuel Schädler',
'threat_actor': 'Unknown',
'title': 'Cyberattack on Liechtenstein’s Beneficial Owners Register Exposes '
'Data of 31,000 Legal Entities',
'type': 'Data Breach'}