The Government of Liechtenstein has reported a serious information security incident. Unidentified perpetrators gained unauthorised access to the specialised Register of Beneficial Owners.
The attack occurred on the night of 29–30 July 2026. Later that day, specialists at the Office of Justice detected irregular activity. The system was subsequently taken offline and protective measures were implemented. The Government was formally notified of a potential successful breach on 31 July. On 1 August, a preliminary investigation confirmed that copies of data relating to approximately 31,000 legal entities — including companies, foundations and trusts — had been extracted.
The VwbP Register was established in 2021 and is maintained for the purpose of preventing money laundering and the financing of terrorism. It contains personal data of individuals who exercise ultimate control over legal structures, including full names, dates of birth, nationality and details of nature and extent of their beneficial interest.
According to the authorities, the data held within the system was neither modified nor deleted; the attackers obtained copies only. At the time of the announcement, no ransom demands had been received, and the stolen information had not been identified on the dark web.
A crisis management team has been established under the leadership of Head of Government Brigitte Haas and Minister of Justice Emanuel Schädler. The team’s priorities are to investigate the incident thoroughly, implement appropriate safeguards and notify affected parties as promptly as possible. Enquiries may be directed to the dedicated email address: vwbpfragen@llv.li. External access to the Register has been suspended.
