DarkReading

Liechtenstein Cyberattack Exposes VwbP Data Breach


The Liechtenstein cyberattack has prompted authorities to investigate a major security breach after copies of sensitive data linked to around 31,000 legal entities were unlawfully accessed from the country’s Register of Beneficial Owners (VwbP).  

Following the cyberattack on Liechtenstein, officials temporarily suspended external access to the register while investigations continue. Although data was exfiltrated, the government said there is currently no evidence that records were altered or deleted. 

Cyberattack on Liechtenstein’s VwbP Register 

According to the Liechtenstein government, the VwbP was targeted during the night of 29/30 July 2026, when unknown attackers gained unauthorized digital access to the system. Irregularities were detected by the Office of Justice on 30 July, prompting the Office of Information Technology to investigate, secure the affected systems, and immediately take the register offline. 

In a statement, the government said, “Copies of data relating to around 31,000 legal entities were unlawfully exfiltrated.” It added that the register would remain unavailable to external users through the llv.li website until further notice. “According to the current state of knowledge, there are no indications that data in the system was modified or deleted,” the statement noted. 

Liechtenstein Cyberattack Triggers Government Response 

The cyberattack on Liechtenstein has highlighted the growing cybersecurity risks facing international financial centres that manage assets for wealthy individuals, businesses, trusts, and other institutions. The VwbP is maintained to support anti-money laundering and counter-terrorist financing efforts by recording the beneficial owners of companies, foundations, trusts, and other legal entities. 

Authorities began reviewing the incident immediately after the suspicious activity was detected. On 31 July, the government was informed that the attack on the VwbP had likely succeeded. Preliminary investigation results were delivered on the afternoon of 1 August 2026, leading the government to establish a crisis unit that same Saturday evening. The unit, formally confirmed the following day, is headed by Prime Minister Brigitte Haas and Minister of Justice Emanuel Schädler.

The Register of Beneficial Owners Act (VwbPG) came into force in 2021, implementing the requirements of the 5th EU Anti-Money Laundering Directive. The government also confirmed that the Liechtenstein cyberattack constitutes a personal data breach under the General Data Protection Regulation (GDPR). 

VwbP Breach Raises Concerns Over Digital Trust 

Commenting on the broader implications of the breach, Steve Lamb, CEO of Kyckr, said registries are becoming critical to Europe’s evolving digital trust framework. “Under the digital trust model taking shape in Europe, the registry stops being a noticeboard we query and becomes the authentic source, a body that can sign a statement about who owns and controls a company, which thousands of institutions then rely on,” he said. 

Lamb added that as registries become trusted sources for verifying ownership, their security becomes fundamental to the wider financial ecosystem. “The debate can’t only be about standards, schemas and interoperability. Registries are becoming critical financial infrastructure, and they should be resourced like it.”  

The digital trust model he referred to is the European Business Wallet, eIDAS 2.0. As investigations into the VwbP breach continue, officials are working to determine the full impact of the Liechtenstein cyberattack. 



Source link