The forensic investigation of the cyberattack on the Register of Beneficial Owners (VwbP) has identified a potential entry point. Further detailed analysis is ongoing. The investigations into how the attack was carried out are continuing, and the criminal prosecution authorities are conducting their inquiries. Over the past 48 hours, the crisis unit has implemented various measures and initiated others.

Initial findings on how the attack was carried out

The Register of Beneficial Owners (VwbP) became the target of a cyberattack in the middle of last week. The forensic investigations and the related analyses of how the attack unfolded and how the security barriers were circumvented are continuing. A first indication of a possible entry point of the attack has been identified. It was a targeted attack, carried out at a high technical level, on a highly complex security structure.

The preliminary results also show that the VwbP was attacked specifically and in an isolated manner. According to the current state of knowledge, no unlawful access attempts were registered either on the National Administration's servers or on other National Administration systems.

Nevertheless, the Government has ordered that, as a precautionary measure, further systems containing sensitive data be temporarily taken offline. These systems are undergoing further comprehensive security checks.

Prime Minister Brigitte Haas emphasises: “We are continuing to work urgently on clarifying the criminal cyberattack and on the measures taken in response to it. I would like to point out once again that the VwbP is an instrument for transparency and for the prevention of criminal offences. We created the register in coordination with our European partners and to implement the 5th EU Anti-Money Laundering Directive. The attack on us is also an attack on international compliance standards.”

The financial centre strategy, drawn up jointly by the authorities and the financial market participants and jointly supported by them, states this very clearly. Among the most important measures are the timely implementation of all relevant EU rules and Liechtenstein’s full integration into the European System of Financial Supervision, as well as the automatic exchange of information in tax matters, the implementation of the OECD initiatives to combat base erosion and profit shifting, and the proactive fight against money laundering and terrorist financing. Full compliance with all international standards and Liechtenstein's pioneering role in combating financial crime are also regularly confirmed by international organisations such as MONEYVAL, the International Monetary Fund, and the rating agency S&P Global.

Affected data subjects are being informed

An important measure is the notification of the data subjects about this attack and their data, as required under data protection law. The General Data Protection Regulation provides for detailed information in this regard. However, since not all contact details – for example, residential addresses – are stored in the register, the legal entities are now being informed of the incident and asked to inform the affected data subjects. As a result, no further data going beyond the Anti-Money Laundering Directive will flow to governmental bodies.

In addition, an information point has been set up as a further channel for questions and information for those affected. It is available starting Tuesday, 4 August 2026, at 4 p.m. by telephone at +423 232 90 00 or by email at vwbpfragen@llv.li. The information point can be reached by telephone on weekdays from 8 a.m. to 12 noon.

No client or asset data affected

Liechtenstein has repeatedly committed itself to a high standard in fulfilling the relevant international and European requirements in the area of combating money laundering and terrorist financing, and implements this commitment consistently. Conformity with international and European standards has been an important pillar of the financial centre strategy for years.

For this reason, the VwbP was introduced in 2021 in the course of implementing the 5th Anti-Money Laundering Directive. This data is used by the bodies entitled to inspect the VwbP for the purpose of combating money laundering, predicate offences to money laundering, and terrorist financing. The register lists the name of the legal entity as well as the surname, first name, date of birth, nationality, and country of residence of the beneficial owners.

No addresses or telephone numbers are recorded. Likewise, no financial data of the legal entities, such as revenues, assets, or dividends, is recorded. Accordingly, no conclusions about assets or other financial data can be drawn from the exfiltrated data. 

Criminal prosecution authorities involved

Over the weekend, the Office of Justice filed a criminal complaint against persons unknown. The prosecution authorities then immediately took up their investigations. Digital traces are being analysed and followed up in cooperation with European authorities.

The Register of Beneficial Owners (VwbP)

The VwbP is maintained for the purpose of preventing money laundering and terrorist financing and follows the requirements of the 5th EU Anti-Money Laundering Directive. It contains public and non-public data on the beneficial owners of companies, foundations, and trusts in Liechtenstein. The Act on the Register of the Beneficial Owners of Legal Entities (VwbPG) entered into force in 2021.