Decoding the world of cybersecurity

Liechtenstein attack exposes ownership register data

Attackers copied beneficial-owner data relating to around 31,000 legal entities, while Liechtenstein suspended several other government systems to check for wider exposure.

Liechtenstein attack exposes ownership register data
Summary
  • Attackers copied data concerning around 31,000 legal entities from Liechtenstein’s Register of Beneficial Owners.
  • Authorities found no indication that register data was changed or deleted, and no further attacks against other systems had been identified.
  • Several tax and reporting services were suspended as a precaution while investigators examined the wider government environment.

Attackers copied beneficial-ownership data relating to around 31,000 legal entities from a Liechtenstein government register, prompting authorities to suspend several other digital services while they checked the wider environment.

The Government of Liechtenstein said unknown attackers obtained unlawful access to the Register of Beneficial Owners, known as the VwbP, during the night of 29 to 30 July. Copies of register data were exfiltrated, although officials have found no indication that records were modified or deleted.

The register contains information about the beneficial owners of companies, foundations, trusts, and other legal entities. It was established under legislation implementing requirements from the European Union’s fifth Anti-Money Laundering Directive and is used to support the prevention of money laundering and terrorist financing.

Irregularities were detected at the Office of Justice on 30 July, after which the government’s information technology office began analysing the affected environment and took the register offline. The government was informed of a potentially successful attack the following day, with preliminary findings confirming unauthorised access on 1 August.

A government crisis unit was convened over the weekend, led by Prime Minister Brigitte Haas and Justice Minister Emanuel Schädler. Authorities have also begun informing affected people under the notification provisions of the General Data Protection Regulation.

Initial forensic findings described the incident as a targeted attack against the register rather than a wider compromise of Liechtenstein’s government infrastructure. No additional attacks against other systems had been identified by 3 August, but several services were suspended to allow further checks.

The systems taken offline included the eMWST value-added tax portal, the Lides electronic reporting and data-exchange platform, the Central Register of Accounts, and the Intax central tax-administration system. The government said those shutdowns were precautionary and that it had no indication of unlawful access to the additional platforms.

The distinction is important, but the operational consequence extends beyond the system from which data was copied. Temporarily withdrawing tax, reporting, and account-register services demonstrates how an incident contained to one application can still disrupt a broader public digital estate while investigators establish whether shared identities, infrastructure, or administrative pathways were exposed.

The affected data also carries a different risk profile from a conventional contact-list breach. Beneficial-ownership registers are intended to make control over legal entities visible to competent authorities and other eligible users. Their contents may therefore reveal relationships between individuals, companies, trusts, and foundations that are relevant to financial investigations, regulatory checks, and commercial due diligence.

Even without alteration of the underlying records, unauthorised copying creates questions about who may use that information, whether individuals represented in the register face additional targeting, and whether data from the incident could be combined with other financial or corporate records.

The attack also tests the resilience of infrastructure built to support European financial-transparency rules. Registers of this kind are not simply administrative databases: they form part of the control environment used by governments, regulated businesses, and investigators to identify who ultimately owns or controls a legal entity.

Liechtenstein’s response has so far separated confirmed compromise from precaution. Officials have confirmed data exfiltration from the VwbP, but have not identified the attacker, published an entry route, or reported evidence that other government systems were accessed.

Criminal-prosecution authorities and external specialists are investigating the intrusion. The attacker, entry route, precise categories of copied data, and consequences for affected people had not been established in the government notices available before a scheduled press conference on 4 August.

×