Summary
- Switzerland's new beneficial-ownership transparency register is due to enter operation under legislation taking effect on 1 October.
- Liechtenstein confirmed the theft of data relating to around 31,000 legal entities from its comparable register.
- Liechtenstein is widening its response from the affected application to procurement, administration, and other sensitive government systems.
Switzerland is continuing towards the 1 October introduction of a central beneficial-ownership register as neighbouring Liechtenstein expands its investigation into a cyberattack that exposed data relating to around 31,000 legal entities.
The Swiss Federal Office of Justice is responsible for the infrastructure supporting the new transparency register, which forms part of legislation designed to strengthen the country’s framework against money laundering and terrorist financing. The register is intended to give authorised public bodies more efficient access to information identifying who ultimately controls legal entities.
The timetable has acquired a more immediate cybersecurity dimension following the compromise of Liechtenstein’s Register of Beneficial Owners. The Liechtenstein government has confirmed that attackers gained unlawful access during the night of 29 to 30 July and copied data associated with approximately 31,000 legal entities.
Investigators subsequently traced the weakness to faulty authorisation logic in the register’s application. Liechtenstein has said there is still no indication that the stolen data has been misused, but the incident triggered a broader review of government systems containing sensitive information.
Several systems were temporarily taken offline as a precaution. On 31 August, the government said it was procuring an additional external review from an international specialist, covering not only the incident itself but other security-sensitive systems and the procurement, control, and administration of government IT.
That wider scope is notable. A failure in a sensitive public database is rarely confined to the vulnerable code path once questions arise about how the system was designed, procured, monitored, and governed. Liechtenstein’s response has moved beyond technical remediation towards examination of the management structures surrounding the affected infrastructure.
The Swiss register is being introduced for a different legal system and on separate infrastructure, and there is no evidence that it shares Liechtenstein’s vulnerability. The neighbouring incident nonetheless illustrates the concentration of risk created when information that was previously dispersed across organisations is brought into a central, authoritative repository.
Centralisation can make regulatory processes more efficient and improve the quality of information available to authorities. It also creates a highly attractive data set whose confidentiality, integrity, and availability need to be protected throughout the register’s lifecycle. Those competing considerations are particularly acute for beneficial-ownership data because the information exists precisely to identify relationships that may otherwise be difficult to establish.
Swiss financial-sector groups have raised concerns about the register’s cyber exposure following the Liechtenstein breach. The current federal timetable remains 1 October, when the Act on the Transparency of Legal Persons and the Identification of Beneficial Owners and related anti-money laundering reforms enter into force and transition towards the new register begins.
Switzerland has already been testing the register’s technical infrastructure and digital processes through a pilot programme. The operational challenge now extends beyond whether the application functions correctly. Identity verification, access control, interface security, monitoring, incident detection, supplier governance, and recovery all become part of the assurance case for a database carrying sensitive ownership information.
Liechtenstein’s experience also shows how disruption can spread beyond the compromised service. Other government systems were taken offline for precautionary checks, creating operational effects even where there was no evidence those systems had been attacked. Its Terris land-register software was due to return to service on 2 September, with other systems to follow after additional checks.
The Swiss launch therefore arrives against a concrete example of the cyber risk attached to concentrated government data. The policy case for ownership transparency has not disappeared, but implementation now carries an unusually visible test of whether the security and governance around the register can support the sensitivity of the information it is being built to hold.




