Cyberattack in Liechtenstein: 31,000 data records copied from secret register of beneficial owners

Vaduz – A cyberattack in Liechtenstein targeted a state-run register of beneficial owners during the night of July 30, 2026. Unknown parties copied data concerning approximately 31,000 companies, foundations, and trusts. The register lists the individuals who actually control these entities; consequently, the stolen information could be of interest for fraud attempts, extortion, or identity theft. Authorities took the system offline and established a crisis management team. However, according to current information, bank accounts, transactions, and bank customer data were not affected.


Cyberattack in Liechtenstein Hits Confidential Register of Beneficial Owners

The Office of Justice detected irregularities on July 30 and alerted the Office of Information Technology. IT specialists subsequently secured the system and halted external access. However, the government did not learn of a potentially successful attack until July 31. On August 1, initial investigation results confirmed a massive data breach.

The cyberattack in Liechtenstein exposes sensitive owner data and increases the risk of fraud and identity theft.
The cyberattack in Liechtenstein exposes sensitive owner data and increases the risk of fraud and identity theft.
Image: Shutterstock

The figure of 31,000 refers to legal entities, not necessarily 31,000 individual people. The government did not initially disclose how many natural persons are affected. However, the register contains the names, first names, dates of birth, nationalities, and countries of residence of the beneficial owners. It also links this information to companies, foundations, or trust structures.

No banking data affected; perpetrators remain unknown

The cyberattack in Liechtenstein involves a highly sensitive dataset. The register is designed to show authorities who actually controls companies and asset structures; Liechtenstein introduced it in 2021 to implement European regulations against money laundering and terrorist financing. External users are currently unable to access the system.

There was no initial evidence that data had been altered or deleted. Furthermore, the government knew neither the perpetrators nor their objective. Head of Government Brigitte Haas stated that there had been no ransom demand and no known offer for sale on the darknet. Nevertheless, authorities are required to notify affected individuals in accordance with data protection regulations.


Switzerland Testing a Comparable Transparency Register

The case extends beyond Liechtenstein, as Switzerland is also establishing a comparable transparency register. Since June 16, 2026, the Federal Office of Justice has been testing the infrastructure using real corporate data. The underlying legislation enters into force on October 1, 2026. The non-public register is intended to record the beneficial owners of Swiss companies and certain foreign legal entities.

However, the cyberattack in Liechtenstein does not prove that the Swiss system has already been compromised. Rather, it illustrates the potential consequences of unauthorized access to centrally aggregated ownership data. Consequently, the security of such a register depends on more than just its statutory purpose; technical isolation, access controls, and the rapid detection of unusual data retrieval activity are equally important.

Author: Blackout News
Sources: Regierung des Fürstentums Liechtenstein (03.08.26)20 Minuten (03.08.26)Reuters (03.08.26)

Scroll to Top