Liechtenstein register hack exposes the privacy risks of financial transparency

Data concerning 31,000 legal entities were stolen from the principality’s beneficial ownership register. As access moves to an identity-checked service in Vaduz, the unresolved question is whether stronger entry controls can protect the people behind the records.

Published
Illustration of an open data vault, exposed identity records and Liechtenstein’s flag against an Alpine backdrop.
Editorial illustration of the cybersecurity and privacy risks surrounding Liechtenstein’s beneficial ownership register.

Liechtenstein’s beneficial ownership register was established to answer a question central to financial investigations: who ultimately owns or controls the legal structures through which money moves?

Known as the VwbP — Verzeichnis der wirtschaftlich berechtigten Personen — the state database identifies the individuals behind companies, foundations and trusts. Its purpose is to assist the fight against money laundering, terrorist financing and associated offences. The principality introduced its predecessor legislation in 2019, implementing requirements of the EU’s fourth anti-money-laundering directive. (regierung.li)

The current framework followed on 1 April 2021, when the VwbPG took effect, incorporating requirements of the fifth directive. The register is administered electronically by Liechtenstein’s Office of Justice, with reporting obligations imposed on the legal entities concerned.

The information is personal, even where the obligation to supply it falls on a corporate structure. The government’s description of the register lists the structure’s name alongside its beneficial owners’ names, dates of birth, nationalities and countries of residence. These records connect identifiable people to particular ownership and control relationships.

That connection is what makes the database useful to investigators. It is also what makes its compromise consequential for those recorded in it.

Who can access Liechtenstein’s beneficial ownership register?

The VwbP is not an unrestricted public search engine.

Its framework provides access for competent authorities, including financial intelligence, supervisory and law-enforcement bodies, in connection with their statutory responsibilities. Separately, eligible banks, financial institutions and other obliged professionals can request disclosure for due-diligence purposes. Their entitlement is not equivalent to a general licence to browse other people’s affairs. (gesetze.li)

Access is not confined to those groups, however. Domestic and foreign individuals and organisations can also apply for information through formal procedures, with requirements depending on the legal structure concerned.

For certain standalone entities, the published third-party application form requires applicants to substantiate why the information is needed for combating money laundering or related offences. For other structures, a separate procedure requires evidence of a qualifying legitimate interest or the specified circumstances involving a controlling participation.

These distinctions matter. Operating the portal to file or update records is not the same as having a legal right to obtain information about someone else. Nor does identifying an applicant, by itself, establish a permissible purpose for disclosure.

The July cyberattack breached this system of controlled access. It did not merely gather information that anyone could already download lawfully.

The July 2026 cyberattack: data copied, external access suspended

According to the government’s chronology, the attack occurred during the night of 29–30 July 2026. The Office of Justice detected irregularities on July 30 and involved the government’s IT office. Preliminary findings reached the government on August 1.

The attackers had unlawfully accessed and copied information concerning approximately 31,000 legal entities. External access to the register was subsequently suspended. (regierung.li)

That figure is not a count of affected individuals, still less a list of 31,000 wealthy people. The authorities have not disclosed the number of natural persons involved. The affected entity records also included structures previously deleted from the register. (regierung.li)

The government has stressed that this was not a breach of banks’ customer systems: account balances, transactions, asset information and banking-advisory records were not affected. The official breach FAQ nevertheless expressly acknowledged a high risk to individuals for the purposes of the GDPR’s notification requirements.

The operational disruption did not suspend every anti-money-laundering safeguard. The Office of Justice retained internal access and could supply extracts on application. Banks and fiduciaries remained subject to their own identification, verification and documentation obligations. (regierung.li)

But maintaining those functions could not reverse the copying of the data. From that point, two distinct tasks confronted the authorities: restoring a usable register and addressing the loss of confidentiality.

The government’s response: restricted access in Vaduz

In its October 2 announcement, the government said the identified vulnerabilities had been repaired and that limited external access would resume on October 5.

It also reported that comparisons with backups had confirmed the records were not altered. Other government systems taken offline as a precaution had undergone security checks and been restored, with electronic identification newly required for some applications. Criminal investigations continued, and there were no indications that the stolen data had been published. (medienportal.regierung.li)

The register’s reopening, however, is considerably more restrictive than a return to ordinary remote access.

Under the Office of Justice’s detailed operating instructions, users must attend the Dienstleistungszentrum Giessen in Vaduz, present a valid passport or identity card and obtain a time-limited, one-time password.

They must bring their own device, use that password to join the on-site Wi-Fi, and then authenticate separately to the register using their usual account credentials or electronic identity. This access procedure works only while they are physically inside the centre.

The available functions principally concern entering, updating and administering entity and beneficial ownership records. Direct generation of PDF extracts remains disabled; those documents require a separate application. Some transactions may require more than one visit. (llv.li)

This is therefore neither a one-off identity check followed by unrestricted home access nor a new public walk-in service for inspecting anyone’s ownership arrangements.

Use of the restricted procedure is voluntary. Statutory deadlines that cannot be met because of the limited availability, including where the procedure is not used, remain suspended. (medienportal.regierung.li)

A broader independent examination is still to come. In an October 2 parliamentary response, Prime Minister Brigitte Haas said procurement was under way for a review covering the incident, selected IT systems and their governance. Results are expected in the first half of 2027. She also said there were no indications of concrete misuse of the copied information.

Why the privacy risks extend beyond bank balances

A beneficial ownership record does not need to disclose a bank balance to have value to a criminal.

Names connected to particular companies, foundations or trusts could help an attacker develop a financial profile, identify relationships or construct a more convincing impersonation attempt. Combined with information obtained elsewhere, such records could support targeted fraud or coercion. These are potential uses of the information, not established consequences of the Liechtenstein breach.

The distinction between privacy and immediate financial loss is important. Someone may retain every franc in their bank account while losing control over sensitive information about their financial relationships.

The fraud infrastructure capable of exploiting personal information is not hypothetical. As Antigua.news reported on the dismantling of the LabHost phishing network, criminals were able to purchase services designed to facilitate impersonation and the theft of identifying information. That case is unrelated to the VwbP attack, but illustrates why a privacy breach cannot be assessed solely by asking whether money was stolen at the same time.

Ownership records also create a concentration problem. Bringing information together can improve verification and allow security resources to be concentrated on one system. Yet, where an attacker gains access across many records, that same consolidation can increase the scale of the exposure.

Dispersing information is not automatically safer: it creates other custodians and access points. The relevant security questions concern the amount of information collected, the permissions governing each user and the extent of the damage possible from a single compromised account or application.

The European Data Protection Board’s security guidance distinguishes confidentiality, integrity and availability. That distinction is particularly relevant here. Confirming that records remain accurate establishes their integrity. Reopening the portal restores some availability. Neither step, by itself, restores confidentiality to information already copied.

The courts had already identified the disclosure problem

The legal concerns predate this attack.

In its November 2022 beneficial ownership judgment, the Court of Justice of the European Union invalidated the requirement that ownership information be accessible in all cases to any member of the general public. It recognised the importance of combating money laundering but found that the interference with privacy and personal-data rights was not strictly necessary or proportionate.

The court specifically addressed the consequences of information being retained and disseminated beyond the register. Online registration and exceptional disclosure restrictions did not, on their own, establish an adequate balance. (curia.europa.eu)

That judgment did not prohibit beneficial ownership registers or access by competent authorities. Nor was it a ruling on Liechtenstein’s cybersecurity. It nevertheless identified a problem that technical access controls must also confront: once information has been copied, restrictions at its original source offer limited control over its subsequent circulation.

Kidnapping and extortion: a risk already recognised in law

The possibility of physical harm is not merely an objection advanced after a breach.

Liechtenstein’s 2021 register legislation expressly recognised disproportionate risks of fraud, kidnapping, extortion, violence and intimidation as grounds for restricting certain disclosures under Article 18. The legislation therefore acknowledged that revealing ownership information could, in particular circumstances, affect personal safety as well as informational privacy.

The Office of Justice’s published disclosure-restriction statistics record no exemptions granted in any of the years 2021–2025. They do not show how many applications were made, so the figures cannot establish whether requests were rejected or simply not submitted.

More fundamentally, an exemption regulates lawful disclosure. It cannot, by itself, protect a record against unlawful extraction.

Italy’s kidnapping history supplies a relevant, but narrower, comparison than claims that leaked financial databases caused the abduction wave of the 1970s and 1980s.

A 1998 parliamentary anti-mafia report, reproduced in the University of Milan’s organised-crime studies journal, described the role of basisti: informants who supplied kidnappers with information about prospective victims and their families’ economic resources. Such sources could include employees or people personally acquainted with the family.

The report recorded the kidnapping of Luigi Rossi in San Donato Milanese in December 1977. He was released three days later without a ransom because the information supplied about his financial resources proved inaccurate. The example shows that perceived wealth, not just verified wealth, could influence victim selection. (riviste.unimi.it)

This evidence supports a warning about the criminal use of financial intelligence. It does not establish that breaches of databases comparable to the VwbP caused those historical kidnappings. Nor has such a connection been established in the Liechtenstein case.

Does in-person access adequately protect personal data?

The new arrangements address identifiable risks. Requiring physical attendance and an identity check adds obstacles to anonymous remote access. Restricting the service to a particular location and reducing its functions also narrows the ways in which the external portal can be used.

Those effects are relevant to containment. They do not, however, establish that the underlying application is secure.

The first distinction is between authentication and authorisation. A passport helps establish who has appeared at the counter. It does not establish which records that person should be permitted to access, change or receive.

OWASP’s application-security guidance calls for minimum necessary privileges, access denied by default and permission checks on every request. These controls operate after a user has identified themselves. A legitimate identity cannot substitute for them.

The second distinction concerns location and device security. A personally owned laptop does not become trustworthy simply because its owner has brought it into a government building.

The US National Institute of Standards and Technology’s zero-trust framework explicitly rejects automatic trust based solely on a user’s physical or network location. It treats the security of devices and the entitlement of users as matters requiring their own checks. That principle is directly relevant to a service operated through visitors’ own equipment.

The published reopening instructions do not provide a technical assessment of those devices or the application’s record-level controls. That does not establish that such safeguards are absent. It means their adequacy cannot be inferred from the passport requirement.

Third, restricting one export function does not resolve every subsequent-use risk. Disabling PDF generation closes a convenient route for producing documents, but is not equivalent to proving that information displayed to an authorised user cannot be retained or passed on.

Finally, the physical-access model carries operational costs. Travel, limited opening hours and repeat visits add friction to filing and updating records. The authorities themselves acknowledge that some workflows may require multiple appearances. Those constraints matter because the anti-money-laundering value of a register depends partly on its information remaining current. (llv.li)

The Financial Action Task Force’s beneficial ownership guidance requires competent authorities to have access to adequate, accurate and up-to-date information. It envisages a registry or an alternative mechanism meeting the relevant requirements, alongside other information sources. The objective is effective identification of ownership, not indiscriminate public disclosure.

The practical assessment therefore has two sides: whether the restrictions reduce unauthorised access, and whether legitimate users and authorities can still fulfil their responsibilities without material gaps or delays.

The published arrangements establish an additional physical barrier. They do not yet demonstrate the security of the whole system or settle the balance between confidentiality and effective access. That assessment requires evidence about permissions, devices, monitoring, disclosure procedures and the operation of the restricted service—not merely the presence of an identity check.

Reopening the register is not the end of the incident

A cyberattack does not automatically prove negligent security. In its December 2023 judgment concerning a breach at Bulgaria’s tax authority, the Court of Justice held that the appropriateness of safeguards requires a concrete assessment. It also held that a controller must demonstrate their adequacy and is not automatically relieved of responsibility because the immediate perpetrator was a criminal third party.

Those distinctions leave substantial questions for Liechtenstein’s independent review. How did the attackers obtain access? Which controls failed to contain it? What testing supports the repairs? And what assistance is being provided to individuals whose information can no longer be assumed confidential?

The questions extend beyond European financial centres. In July, Antigua.news reported Antigua and Barbuda’s plans for a national computer incident response team, involving banks, telecommunications companies and other digital-service providers. That initiative concerns a different jurisdiction and does not imply comparable vulnerabilities. It does underline the institutional coordination required when sensitive information and digital services are at risk.

For Liechtenstein, the October 5 reopening is a planned operational milestone. The later review may establish whether the safeguards were appropriate and where responsibility lies.

Neither event, by itself, can account for every copy of the stolen information.

The register was created to make ownership visible to those legally entitled to investigate it. The unresolved security question is how to preserve that capability without making the people behind the records visible to those who have no such entitlement. A repaired portal can restore access. It cannot, on its own, restore control over information that has already escaped.

Dario Item

About the author

Dr. Dario Item is the Head of Mission of the Embassy of Antigua and Barbuda in Madrid. He is an experienced financial crimes lawyer with nearly 30 years of practice. He holds degrees in law and political science, a Ph.D. in criminal law and an LL.M. in transnational financial crime.

Read our editorial standards and corrections policy. Spotted an error? Contact the newsroom.

Comments

Be the first to comment.

Submit a comment

More from Business and Finance

View section