Skip to content

Cyberattack on Liechtenstein: Data of 31,000 individuals stolen from beneficial ownership register

In brief: A cyberattack on Liechtenstein resulted in the theft of data belonging to 31,000 individuals from the beneficial ownership register, prompting the government to set up a crisis team.

The Principality of Liechtenstein has become the target of a large-scale cyberattack in which data belonging to 31,000 people was exfiltrated from the “Register of Beneficial Owners.” The government has established a crisis team led by Head of Government Brigitte Haas and Minister of Justice Emanuel Schädler.

According to the Liechtenstein government, personal data of around 31,000 individuals was compromised in the attack. Affected is the “Register of Beneficial Owners,” which contains names and other information on individuals who stand behind companies, foundations, or trusts. According to the government, this register is maintained to prevent money laundering and terrorist financing. Authorities are officially describing the incident as a breach of the protection of personal data and have set up a crisis team led by Head of Government Brigitte Haas and Minister of Justice Emanuel Schädler to manage the incident.

For CISOs in the DACH region, the incident is relevant for several reasons. First, it shows that government-run registers containing highly sensitive compliance data — in this case relating to beneficial owners in the context of anti-money-laundering prevention — represent an attractive attack target, the compromise of which can have far-reaching consequences for affected individuals, companies, and financial intermediaries. Second, the case underscores the importance of robust access controls and monitoring mechanisms at government agencies with which regulated financial-sector companies regularly exchange data as part of due-diligence obligations (e.g., KYC, AML).

With around 41,000 inhabitants and an area of 160 square kilometers, Liechtenstein is one of the smallest countries in the world, yet one of the wealthiest measured by GDP per capita. Financial and banking services are among the country’s most important economic sectors; banking secrecy in tax matters was abolished in 2017. The government has not yet released further technical details on the attack vector, the duration of the compromise, or possible perpetrators.

Companies with business relationships involving Liechtenstein-based structures should monitor the further course of the official investigation and check whether their own reporting obligations — for example under the GDPR or comparable data protection regulations — are affected by the incident, in cases where personal data of their own stakeholders may be involved.


Source: www.it-daily.net · Published August 3, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: