The Cyberattack That Shook Liechtenstein: What Data Was Stolen and Why Does the Case Affect 31,000 Entities?

The small Principality of Liechtenstein is facing one of the most delicate cybersecurity incidents in its recent history. At the end of July, unknown individuals illegally gained access to the Register of Beneficial Owners — officially known as VwbP — and copied information related to around 31,000 legal entities. The attack affected companies, foundations, and trusts registered in the country and placed particular pressure on a public infrastructure that is especially sensitive for the fight against money laundering and terrorist financing.

The news was communicated by the Liechtenstein authorities at the beginning of August and was subsequently reported by Reuters. The preliminary investigation established that the attackers had managed to enter the register during the night of July 29 to 30, 2026, and extract copies of the data. The authorities detected irregularities on July 30 and proceeded to disconnect the affected system.

The incident has a particular feature that makes it especially relevant: the attacked register is not just any commercial database. Its purpose is precisely to identify the natural persons behind legal structures, a central function that enables authorities to know who actually owns or controls certain companies, foundations, and trusts. The attack, therefore, was not limited to compromising administrative information. It put at risk a set of data designed to provide transparency in one of the most sensitive areas of the international financial system.

A Cyberattack Discovered at the End of July

According to the official reconstruction, the cyberattack began during the night of July 29 to 30. During that period, individuals who have not yet been identified managed to gain unauthorized digital access to the Register of Beneficial Owners. On July 30, employees of the Office of Justice detected irregularities and requested the intervention of the Office of Information Technology to analyze what had happened and determine the scope of the cyberattack.

ITD Consulting analiza el ciberataque a Liechtenstein y los datos de 31.000 entidades

The initial investigation confirmed that this was not simply an unsuccessful intrusion attempt. The attackers had managed to access the register and extract copies of data corresponding to approximately 31,000 legal entities. On July 31, the Government received information that a successful cyberattack may have occurred, and on August 1 it received the first confirmed results of the preliminary investigations.

The initial response to the cyberattack was to disconnect the affected system and begin a forensic analysis. The authorities also created a crisis unit led by Prime Minister Brigitte Haas and Justice Minister Emanuel Schädler. The stated objective was to quickly clarify the cyberattack, protect public systems, and determine what information had been copied during the intrusion.

One of the first relevant conclusions was also one of the few reassuring pieces of news: so far, there were no indications that the attackers had modified or deleted the data stored in the register. In other words, the available evidence mainly points to an extraction of information caused by the cyberattack, rather than to an alteration of the database.

This does not mean, however, that the impact of the cyberattack is minor. A legitimate copy of a database can remain perfectly useful to an attacker even if the original remains intact. The risk lies precisely in the fact that the information stolen during the cyberattack could be analyzed, cross-referenced with other sources, used to identify individuals, or subsequently employed in fraud, extortion, impersonation, or social engineering operations.

What Is the Register of Beneficial Owners?

To understand the importance of the cyberattack, it is necessary to understand what information the VwbP stores. The Register of Beneficial Owners was created as part of Liechtenstein's process of adapting to European anti-money laundering rules. The legal framework began to be developed based on the requirements of the Fourth European Anti-Money Laundering Directive and was subsequently expanded with the requirements of the Fifth Directive. The specific legislation on the register of beneficial owners entered into force in 2021. Precisely because of the nature of this information, the cyberattack against the register has raised concern both because of the amount of data affected and because of the sensitivity of the ownership relationships that may be exposed.

The concept of a beneficial owner is fundamental for financial authorities. A company may have a complex legal structure and formally appear to be controlled by certain entities or representatives. However, behind that structure there is usually a natural person who ultimately owns or controls the organization. Identifying that person allows authorities to assess risks related to money laundering, terrorist financing, and other illicit activities. The register contains information about the people who hold that status. Among the data affected by the cyberattack may be the name of the legal entity and, with respect to its beneficial owners, the first and last name, date of birth, nationality or nationalities, and country of residence.

Liechtenstein authorities have also emphasized what information does not appear in the register. It does not contain private addresses or telephone numbers. Nor does it include financial data such as income, wealth, dividends, or assets of the entities. This is important because it prevents the leak resulting from the cyberattack from automatically being interpreted as a direct exposure of bank accounts or personal fortunes. The difference is substantial. The register may reveal who is behind a particular legal structure, but it does not, by itself, provide a complete inventory of that person's assets. The main security problem generated by the cyberattack therefore focuses on the relationship between identity and legal structure, information that can be highly valuable even without financial figures.

31,000 Entities Does Not Mean 31,000 People

One of the first misunderstandings to arise around the case is related to the figure of 31,000. The authorities refer to approximately 31,000 affected legal entities, not 31,000 natural persons. An entity can be a company, a foundation, or a trust and may have one or more beneficial owners. In addition, the group of affected entities includes some that had already been removed from the register. For legal and investigative reasons, the authorities have not published the exact number of natural persons affected by the cyberattack.

The figure, therefore, does not make it possible to directly determine how many individuals have been exposed. It does, however, make it possible to assess the scale of the intrusion and the cyberattack against the register. These are thousands of legal structures whose ownership links potentially ended up in the hands of unauthorized third parties. This point is especially important in a country such as Liechtenstein, whose economy is closely linked to financial services, wealth management, and international legal structures. The Principality is one of the smallest countries in the world and, at the same time, has a financial sector of international significance.

Reuters specifically highlighted the importance in Liechtenstein of trusts and other low-tax structures. At the same time, the Liechtenstein Bankers Association clarified that the systems of the banks and their customers' data had not been affected by the cyberattack known so far. This distinction is fundamental: the incident affects the state register of beneficial owners, but it does not mean that the country's entire financial system has been penetrated as a result of this cyberattack.

The Government Denies That It Was a Cyberattack on the Financial Center

The authorities have insisted that there are no indications that the cyberattack compromised the systems of private financial institutions. The register is operated by the State and is under the responsibility of the Liechtenstein Administration. According to the information available, the cyberattack was specifically directed against that infrastructure. The preliminary investigations did not detect attempts to gain illicit access to the general servers of the National Administration or to other administrative systems.

This circumstance led the Government to describe the cyberattack as targeted and technically sophisticated. The forensic investigations identified an initial clue regarding a possible entry point, although the authorities have not made public the specific technique used by the attackers or attributed the incident to a particular group.

The absence of a public attribution is relevant. In the first days of an investigation of this kind, determining who carried out a cyberattack can be considerably more difficult than proving that an intrusion occurred. Digital traces can be manipulated, the servers used for access may be located in third countries, and attackers may resort to infrastructure that had previously been compromised. For this reason, the fact that the authorities know that the data was copied does not mean that they know who has it or what the ultimate objective of the cyberattack was.

A Response That Expanded After the Cyberattack

The Government's response was not limited to disconnecting the VwbP. Given the possibility that the cyberattack could reveal broader vulnerabilities, the authorities began reviewing other public systems containing sensitive information. Four state systems were initially disconnected as a preventive measure. On August 5, the crisis unit decided to expand the review to other systems and temporarily keep offline those that might require additional controls.

ITD Consulting: el ciberataque que expuso datos de 31.000 entidades en Liechtenstein

The strategy reflects one of the main difficulties of responding to a cyberattack against a public administration: as long as it is not known precisely how the attacker managed to gain entry, it is difficult to determine with absolute certainty which other systems might share a vulnerability. The Government has indicated that the available investigations show no evidence that the country's critical infrastructures are affected. The National Cybersecurity Unit remains in contact with the operators of those infrastructures to assess the situation and rule out possible consequences arising from the cyberattack.

The preventive disconnection of systems can generate operational and administrative problems, but it also constitutes a common containment tool. In a situation of uncertainty, keeping a system connected can be riskier than temporarily suspending its functions while a technical analysis is carried out. This measure makes it possible to limit the potential effects of a cyberattack and provides specialists with a more controlled environment in which to investigate how the intrusion occurred.

The Data Protection Dimension

The case also has a legal dimension. The Government of Liechtenstein has classified the cyberattack as a personal data breach within the meaning of the General Data Protection Regulation, known as the GDPR. The regulation establishes specific obligations for data controllers when a personal data breach occurs. In this case, the authorities notified the incident to the data protection authority within the applicable timeframe and began informing the affected individuals through the legal entities related to them. Since August 4, an information channel has also been made available to answer questions from potentially affected individuals.

The most delicate element is that the stolen information is not necessarily secret information in the traditional sense. The purpose of a register of beneficial owners is precisely to allow certain levels of access to information about who controls a legal structure. However, the fact that data is legally accessible to certain authorities or authorized persons does not mean that it can be copied and used without restrictions by a third party. Information security does not depend solely on whether data is one hundred percent confidential. It also matters who can access it, for what purpose, for how long, and under what controls, especially when a cyberattack occurs that allows large quantities of information to be extracted.

Why Could the Leak Have Consequences Beyond Liechtenstein?

The international nature of the Principality's legal structures potentially broadens the scope of the cyberattack. A company or foundation registered in Liechtenstein may be linked to individuals residing in other countries. The register, precisely because of its purpose, links legal entities to the natural persons who ultimately control or own them. Therefore, a leak caused by this cyberattack does not exclusively affect residents of Liechtenstein. It may involve citizens of numerous countries who have some legal or economic connection to a structure registered in the Principality.

The stolen information can acquire particular value when combined with other databases. A name, a date of birth, a nationality, and a country of residence may appear insufficient on their own. But when cross-referenced with commercial registers, public documents, previous leaks, professional networks, or information published on the internet, they can contribute to creating much more complete profiles. This phenomenon, known as data correlation, is one of the main problems of modern data breaches. The danger is not always found in a single piece of extremely sensitive information, but in the possibility of bringing together many apparently harmless pieces of information. In the context of a cyberattack, this ability to combine data can considerably increase the value of the stolen information and broaden its potential consequences far beyond the system originally compromised.

The Criminal Investigation Enters a New Phase

On August 6, an important development took place. The Liechtenstein Public Prosecutor's Office asked the country's Court of Justice to authorize preliminary proceedings against unknown perpetrators. The National Police had already submitted an initial investigation report to the Public Prosecutor's Office. The proceedings are being conducted on suspicion of illegal access to a computer system and data theft, in accordance with the relevant provisions of the Liechtenstein Criminal Code. This step does not mean that the authorities have identified the person responsible for the cyberattack. Precisely, the proceedings are directed against unknown perpetrators while investigators continue to follow the digital traces left during the intrusion.

The investigation will have to answer several fundamental questions: how the initial access occurred, what vulnerability allowed the security barriers to be breached, how long the attackers remained inside the system, what exact information they copied, and what infrastructure they used to extract it. It will also be necessary to determine whether the cyberattack was exclusively against the VwbP or whether it forms part of a broader operation.

The True Scale of the Incident

The number of 31,000 entities is the most striking element of the case, but it is probably not the most important indicator. The true scale of the breach will depend on what happened to the data after it was copied. If it remained solely in the hands of the attackers, the risk will be different from what it would be if the data were transferred, sold, or published. It will also be decisive to know which individuals appear in the affected structures and what other sources of information can be combined with the data stolen during the cyberattack.

For now, the authorities have confirmed the illegal access, the extraction of copies, and the impact on around 31,000 entities. They have also indicated that there is no evidence of modification or deletion of the original data, that banking systems and customer data have not been affected, and that the country's critical infrastructure currently shows no signs of having been compromised as a result of the cyberattack.

The investigation will have to turn those initial conclusions into a complete reconstruction of the cyberattack. In the meantime, the episode leaves one clear conclusion: in a world where financial transparency increasingly depends on large digital systems, protecting information about the real owners of companies and asset-holding structures is just as important as collecting it. Liechtenstein created its register to help combat illicit money and determine who actually controls certain entities. Now it must face the reverse challenge: finding out who managed to enter that register, what information they managed to copy during the cyberattack, and how to prevent it from happening again.

The outcome of that investigation will not only determine responsibility for a cyberattack against a state institution. It may also become a test for the European model of corporate ownership transparency: a model that needs to gather sufficient information to combat financial crime, but that at the same time must ensure that this information does not become an easy target for those precisely seeking to take advantage of it.

ITD Consulting y el ciberataque que puso en riesgo datos de 31.000 entidades reales

The cyberattack against Liechtenstein's Register of Beneficial Owners demonstrates that no system storing sensitive information is completely beyond the reach of digital threats. Although the authorities have indicated that the country's banking systems, customer data, and critical infrastructures show no signs of having been compromised, the extraction of information related to approximately 31,000 legal entities demonstrates the extent to which a vulnerability can have significant consequences when it affects a database containing personal and corporate information.

The case also highlights that cybersecurity should not be understood solely as a technical matter. Preventing a cyberattack involves protecting systems, but also identifying vulnerabilities, controlling access, monitoring infrastructures, establishing response protocols, and having appropriate mechanisms in place to quickly detect any anomalous behavior. Liechtenstein's experience therefore serves as a warning for companies and organizations of any size. Cybercriminals do not necessarily need to access banking or financial information to cause a significant impact. Identity data, business relationships, and corporate information can have enormous value when combined with other sources or used for social engineering, fraud, and identity theft attacks.

Having an adequate cybersecurity strategy makes it possible to reduce risks, protect critical information, and improve an organization's ability to respond to potential incidents. If your company needs to strengthen its protection against cyberattacks, assess its vulnerabilities, or improve the security of its systems and data, ITD Consulting can help you design and implement IT and cybersecurity solutions tailored to your organization's needs. To learn about its services and analyze how to better protect your technological infrastructure, you can write to [email protected]

Do you want to SAVE?
Switch to us!

✔️ Corporate Email M365. 50GB per user
✔️ 1 TB of cloud space per user

en_USEN

¿Quieres AHORRAR? ¡Cámbiate con nosotros!

🤩 🗣 ¡Cámbiate con nosotros y ahorra!

Si aún no trabajas con Microsoft 365, comienza o MIGRA desde Gsuite, Cpanel, otros, tendrás 50% descuento: 

✔️Correo Corporativo M365. 50gb por usuario.

✔️ 1 TB of cloud space per user 

✔️Respaldo documentos.

Ventajas: – Trabajar en colaboración Teams sobre el mismo archivo de Office Online en tiempo real y muchas otras ventajas.

¡Compártenos tus datos de contacto y nos comunicaremos contigo!