Summary
- Liechtenstein’s beneficial owner register reopened to external users on 5 October after being unavailable since a July cyberattack.
- Access initially requires personal identification and use of the system at a government facility in Vaduz.
- Statutory deadlines remain suspended where restricted availability prevents required filings.
Liechtenstein has resumed restricted external access to its beneficial owner register more than two months after a cyberattack forced the government to close the system to outside users.
The country’s Office of Justice said operations resumed on 5 October after identified vulnerabilities had been addressed, although the Register of Beneficial Owners of Legal Entities, known as VwbP, is not returning immediately to its previous access model.
Users must first undergo personal identification at the Migration and Passport Office in Vaduz, presenting a valid passport or identity card. Subsequent use of the register is also restricted to the government’s Dienstleistungszentrum Giessen facility and provides a reduced range of technical features.
The temporary arrangement follows the cyberattack of 30 July, after which external access to the register was withdrawn. Earlier investigation established that attackers had copied beneficial ownership information, prompting a broader security review across government systems.
Resuming the service under tighter controls separates basic operational recovery from a full return to normal. Authorities can restore access for users who need the register while reducing remote exposure until they are satisfied that identity, authentication and connected systems can support a less restrictive model.
Beneficial owner registers contain information intended to identify the individuals who ultimately own or control legal entities. Their role in anti-money laundering and corporate transparency means prolonged unavailability can affect companies, professional advisers and public bodies that depend on the register for statutory processes.
Liechtenstein has kept relevant legal deadlines suspended where users cannot comply because of the register’s restricted availability or choose not to use the temporary on-site procedure. That reduces pressure to treat a constrained technical service as equivalent to full restoration.
The access model also moves part of the security boundary away from remote authentication. Personal identification and use of the system now take place inside a controlled government environment, limiting who can connect from outside while recovery work continues.
That protection creates operational friction for legitimate users who previously relied on online access. Travel to Vaduz and reduced functionality make the process less convenient, but they allow the government to reopen a legally important service without reinstating the same technical exposure immediately.
Cyber recovery frequently involves that trade-off. Keeping an administrative platform offline can interrupt statutory activity, while restoring every feature at once can reintroduce risk before investigators have completed remediation and validation.
Because public digital services connect identity systems, databases, networks and external users, confidence in one repaired component may not be enough to justify full restoration. Organisations also have to establish whether credentials remain trustworthy, whether connected services were affected and whether monitoring can identify renewed intrusion.
Liechtenstein has not announced a date for unrestricted remote access to return, and the Office of Justice says the temporary arrangements will continue until further notice. The current reopening therefore indicates that enough functionality has been restored for controlled use rather than that the wider recovery programme has ended.
The incident provides a European example of cyber impact continuing long after the initial breach. Data theft occurred in July, but the consequences in October include altered identity checks, reduced digital functionality, suspended deadlines and a continuing change to how external users reach a government service.
How long those controls remain in place will depend on the government’s assessment of the rebuilt environment and the permanent changes introduced following the attack.





