
Hacker breaches Liechtenstein’s beneficial-ownership register, stealing data on 31,000 entities
Unidentified attackers copied sensitive personal information from a government database meant to combat money laundering, threatening the principality’s reputation for data protection.
Cyber criminals gained unauthorised access to Liechtenstein’s Register of Beneficial Owners (VwbP) during the night of 30 July, exfiltrating data on roughly 31,000 legal entities, the government confirmed on Sunday. The register, created in 2021 to implement the EU’s fifth anti-money-laundering directive, holds the names, birth dates, nationalities and residential countries of the natural persons who ultimately control or benefit from companies, foundations and trusts domiciled in the principality. After the Office of Justice detected irregularities on the day of the breach, the IT authority took the affected system offline and began forensic analysis.
The attack appears to have been narrowly targeted: the government stated that no other databases were compromised, though several were temporarily disconnected as a precaution. Investigators have found no evidence that records were altered or deleted, and no ransom demand or posting of stolen data on the darknet has been reported. Prime Minister Brigitte Haas and Justice Minister Emanuel Schädler immediately convened a crisis staff, and the Office of Informatics is working with external partners to determine the perpetrators and the method of entry.
The breach strikes at the heart of Liechtenstein’s identity as a financial centre that markets itself on legal certainty and the protection of sensitive client data. The Liechtenstein Bankers Association stressed that no bank or bank-customer information was taken, but the disclosure of the register’s contents exposes individuals who often seek anonymity – many of them foreign nationals. Rainer Kirchdörfer, head of the Foundation for Family Businesses and Politics in Germany, warned that the incident illustrates the risk inherent in collecting personal business data in public registries, especially ahead of planned EU rules that from 2027 would require inclusion of private residential addresses and passport numbers.
The crisis staff is now tasked with informing all affected individuals and restoring the system’s security. Criminal investigations by the national authorities are under way; no suspects have been identified. The next factual milestone will be the publication of the forensic report, which the government has promised to share once completed, and any further official statements on the origin or motive of the attack.
| Russian & CIS press | 0.00 | neutral |
|---|---|---|
| Continental European press | −0.30 | critical |
Russia reports the attack as a technical incident, without dramatising the implications for Liechtenstein's financial system.
By describing the event as a normal incident and citing the official response (task force), the narrative normalises the occurrence and reduces its scandalous scope.
It omits the debate about the vulnerability of the tax haven and the potential long-term economic consequences.
Continental Europe denounces the fragility of Liechtenstein's secrecy system and warns about the consequences for the entire financial sector.
Through the use of terms like 'nightmare' and 'blow to the heart', the narrative amplifies emotional impact and links the incident to a structural crisis of trust.
It does not mention the creation of the government task force or the immediate political reaction, which could have lessened the sense of vulnerability.
Broaden your view
US Senate votes 86-11 to advance Russia sanctions bill authorising 100% tariffs on top energy buyers
7 languages · 40 outlets
From Economy & MarketsUS imposes 15% tariff and price floors on polysilicon to counter China’s supply-chain dominance
4 languages · 16 outlets
From Science & HealthAI designs first functional viral genomes, raising hopes and biosecurity alarms
3 languages · 24 outlets