jump to content jump to footer

Header area

Content area

In focus  

Cyberattack on the VwbP: latest information

    What happened?

    During the night of 29/30 July 2026, unknown perpetrators gained unlawful access to the VwbP by digital means. In the course of the day on 30 July 2026, irregularities were noticed at the Office of Justice. The Office of Information Technology was subsequently contacted to analyse the situation. On the afternoon of 1 August 2026, the first confirmed results of the preliminary investigations were transmitted to the Government.

    It has been established that the perpetrators were able to gain unlawful access to the register and exfiltrate copies of data relating to around 31,000 legal entities. The VwbP contains information on the beneficial owners of legal entities. As a result of the incident, the register is not available to external users via the website www.llv.li for the time being. According to the current state of knowledge, there are no indications that data in the system was modified or deleted.

    The forensic investigations and the related analyses of how the attack unfolded and how the security barriers were circumvented are continuing. A first indication of a possible entry point of the attack has been identified. It was a targeted attack, carried out at a high technical level, on a highly complex security structure. The preliminary results also show that the VwbP was attacked specifically and in an isolated manner. According to the current state of knowledge, no unlawful access attempts were registered either on the National Administration's servers or on other National Administration systems. Nevertheless, the Government has ordered that, as a precautionary measure, further systems containing sensitive data be temporarily taken offline. These systems are undergoing further comprehensive security checks.

    What measures have been taken?

    Based on the initial suspicion, the Office of Information Technology immediately implemented measures to secure the data and took the affected system offline. At the same time, a comprehensive analysis of the incident was initiated. On 31 July 2026, the Government was informed that a potentially successful attack on the VwbP had taken place. On the afternoon of 1 August 2026, the first confirmed results of the preliminary investigations were transmitted to the Government.

    Following the criminal attack on the Register of Beneficial Owners (VwbP), four state systems were taken offline as a precautionary measure in order to subject them to additional security checks. On 5 August, the crisis unit decided to review further systems and to take them offline temporarily for this purpose.

    The National Cyber Security Unit is in contact with the operators of critical infrastructures in order to assess the situation on an ongoing basis. The National Cyber Security Unit's inquiries to date give no indication that critical infrastructures are affected. Meanwhile, the prosecution authorities' investigations to find the perpetrators are proceeding urgently.

    Information for those affected

    The telephone information point started work on Tuesday, 4 August 2026. It can be reached at +423 232 90 00 on weekdays from 8 a.m. to 12 noon.

    As a further information channel for those affected, the Government has set up an email address at the Office of Justice (vwbpfragen@llv.li), which has received around 50 inquiries since Monday. 

    What is the VwbP?

    The Register of Beneficial Owners (VwbP) was introduced in Liechtenstein to implement the European anti-money laundering directives. The Act on the Register of Beneficial Owners of Domestic Legal Entities (VwEG) first entered into force in 2019, implementing the requirements of the 4th EU Anti-Money Laundering Directive. The aim is to strengthen the fight against money laundering, terrorist financing, and related offences.

    The 5th EU Anti-Money Laundering Directive expanded the requirements for the register. These include, in particular, greater transparency, additional obligations to report discrepancies, extended rights of inspection, and stronger supervision and control. In addition, the previous distinction between the German terms “wirtschaftlicher Eigentümer” and “wirtschaftlich berechtigte Person” (both “beneficial owner” in English) was abolished and the terminology aligned with the due diligence legislation.

    The current register contains information on the beneficial owners of legal entities and serves the competent authorities and certain obliged entities as an important instrument for preventing money laundering and terrorist financing.

    The register contains data on the beneficial owners of legal entities. Legal entities include companies, foundations, and trusts. It records the name of the structure as well as the surname, first name, date of birth, nationality, and country of residence of the structure’s beneficial owners.

    The Act on the Register of the Beneficial Owners of Legal Entities (VwbPG) entered into force in 2021.

    Data protection

    The attack on the VwbP constitutes a personal data breach within the meaning of Article 33 of the General Data Protection Regulation (GDPR). 

    Under Article 34 of the General Data Protection Regulation, the data subjects affected by the data theft must be informed. In addition to the public communication, the letters asking the legal entities to inform the beneficial owners of the personal data breach have been going out since Tuesday, 4 August 2026. The data protection requirements have thus been implemented.

    News

    FAQ

    • A total of around 31,000 legal entities are affected by the cyberattack, including entities that had already been deleted. For legal entities that are entered in the Commercial Register but for which no beneficial owners are required to be recorded in the Register of Beneficial Owners (VwbP) under the statutory requirements, no information on beneficial owners accordingly appears in the VwbP’s electronic system.

    • The data concerned comprises the name/designation of the legal entities and the information on the legal entities' beneficial owners, i.e. the role(s), surname, first name, date of birth, nationality (or nationalities), and country of residence of the legal entity's beneficial owners. A beneficial owner is the natural person who ultimately owns or controls the legal entity.

      According to the current state of information, the data affected is that contained in the most recently completed version of the data entry in the VwbP or whose data entry had the status “In Bearbeitung” (in progress) or “In Mutation” (undergoing modification) at the time of the data protection incident.

    • The Office of Justice has analysed the group of persons affected by the cyberattack. For legal and investigative reasons, no information about this group of persons can be communicated.

    • According to the current state of knowledge, there are no indications that data was modified or deleted. The system was taken offline as a precaution.

      Before the system is brought back into operation, its integrity and security will be comprehensively reviewed. Responsibility for review lies with the competent public bodies.

    • It is currently not possible to generate extracts directly from outside, but applications can be submitted to the Foundation and Trust Supervision and Anti-Money Laundering Division (STIFTA/GWP) of the Office of Justice, which can still access the VwbP internally.

      The temporary unavailability of the VwbP may affect individual verification processes. It should be noted, however, that persons subject to due diligence, such as banks and trust companies, must comply with their own statutorily prescribed verification, identification, and documentation procedures.

      The unavailability of individual registers therefore does not mean that the anti-money laundering controls performed by persons subject to due diligence are suspended.

    • No. It is an attack by unknown perpetrators on the state-operated Register of Beneficial Owners of Legal Entities.

      The market participants' systems and their client data are not affected.

    • The scale of the incident is considerable and must not be downplayed. Precisely for this reason, full clarification, transparent communication, and effective consequences are required. The Government and the authorities responded immediately and established a crisis unit.

      For an assessment, however, the results of the ongoing investigation must be awaited. At this point in time, it would be premature to determine technical, organisational, or personal responsibilities.

    • No. The incident concerns data from a state register, not data held by banks in the context of their client relationships. Bank client secrecy as well as account, asset, transaction, and advisory information are not affected.

    • No. The incident concerns data from a state register, not data held by insurance companies in the context of their client relationships.

    • No, there are currently no indications as to the perpetrators or the motives. The Government will not speculate about possible motives.

    • It constitutes a personal data breach within the meaning of Article 33 of the General Data Protection Regulation (GDPR) – specifically, a case in which unauthorised third parties unlawfully gained access to personal data. Article 33 requires the incident to be notified to the data protection supervisory authority within 72 hours. If not all details of the incident are yet known, a preliminary notification must be submitted. This notification was made within the deadline.

    • Under Article 34 of the General Data Protection Regulation (GDPR), data subjects must be informed if the breach poses a high risk to them. This possibility must clearly be assumed in the present situation. For this reason, they must be informed without undue delay. According to Recital 87, “the fact that the notification was made without undue delay should be established taking into account in particular the nature and gravity of the personal data breach and its consequences and adverse effects for the data subject”. A press conference such as the one held on the evening of 2 August 2026 counts as a first information measure under Article 34 GDPR.

    • Those affected and market participants can direct questions to vwbpfragen@llv.li or by telephone on +423 232 90 00 (on weekdays from 8 a.m. to 12 noon). The email address is managed by the Office of Justice, and expert information will be provided.

    • A criminal complaint has been filed, and investigation proceedings have been initiated. The Office of the Public Prosecutor has applied to the Liechtenstein Court of Justice for preliminary inquiries against unknown perpetrators on suspicion of illegal access to a computer system under §118a(1)(1) and §118a(2) of the Criminal Code (StGB) and data theft under §131a StGB.

    • Yes, two systems, the electronic VAT system (eMWST) and the electronic reporting and data exchange platform Lides, were proactively taken offline. This is a purely precautionary measure. There is no indication that an attack could have taken place on these systems.

      In addition, it was decided to proactively take the Central Register of Accounts (ZKR), the tax administration system Intax, the Terris system, and the goAML web portal of the Financial Intelligence Unit (FIU) offline as well. This, too, is a purely precautionary measure, and there is no indication of a vulnerability.

      The systems are now undergoing additional comprehensive security checks.

    • No.

    • No. This serious incident must be rigorously investigated, but it does not yet permit any sweeping conclusions about the cybersecurity of an entire country. This is a criminal attack.

      What is decisive for trust is how an incident is detected, contained, clarified, and dealt with. This includes transparency, clear responsibilities, and the swift implementation of the necessary improvements.

      In this case, the attack was detected quickly, and the system was immediately taken offline as a result. The public was informed transparently. Comprehensive analyses are currently under way. The Government's top priority is to fully clarify the incident as quickly as possible, inform those affected, and initiate countermeasures.

    • Trust is not based on the possibility of ruling out cyber risks entirely. Trust is created by robust protection systems, clear processes, transparency, and a rigorous response to incidents.

      In this specific case, no client data on the market participants' systems was compromised. The security of client funds and services is not affected.

    • No. It changes nothing about the zero tolerance of Liechtenstein and its financial centre towards money laundering and terrorist financing. The rigorous investigation and remediation of the incident are part of a credible and effective integrity system.

    • The incident is highly regrettable and must not be trivialised. For long-term reputation, however, what is decisive is not merely that a cyber incident has occurred, but above all how it is handled.

      Trust requires that such an incident be clarified quickly, transparently, and completely, and that the necessary consequences be drawn from the findings. The Government takes the incident very seriously and immediately established a crisis unit, which is working urgently on clarifying it. The associations are in close contact with the authorities and the Government in this regard.

      What matters now is to maintain the existing trust through determined action and open communication.

    Which and how many legal entities are affected?

    A total of around 31,000 legal entities are affected by the cyberattack, including entities that had already been deleted. For legal entities that are entered in the Commercial Register but for which no beneficial owners are required to be recorded in the Register of Beneficial Owners (VwbP) under the statutory requirements, no information on beneficial owners accordingly appears in the VwbP’s electronic system.

    What data is affected?

    The data concerned comprises the name/designation of the legal entities and the information on the legal entities' beneficial owners, i.e. the role(s), surname, first name, date of birth, nationality (or nationalities), and country of residence of the legal entity's beneficial owners. A beneficial owner is the natural person who ultimately owns or controls the legal entity.

    According to the current state of information, the data affected is that contained in the most recently completed version of the data entry in the VwbP or whose data entry had the status “In Bearbeitung” (in progress) or “In Mutation” (undergoing modification) at the time of the data protection incident.

    How many natural persons are affected?

    The Office of Justice has analysed the group of persons affected by the cyberattack. For legal and investigative reasons, no information about this group of persons can be communicated.

    Is the Register of Beneficial Owners still reliable after the attack?

    According to the current state of knowledge, there are no indications that data was modified or deleted. The system was taken offline as a precaution.

    Before the system is brought back into operation, its integrity and security will be comprehensively reviewed. Responsibility for review lies with the competent public bodies.

    Can the business associations currently still use the VwbP to fulfil their due diligence obligations?

    It is currently not possible to generate extracts directly from outside, but applications can be submitted to the Foundation and Trust Supervision and Anti-Money Laundering Division (STIFTA/GWP) of the Office of Justice, which can still access the VwbP internally.

    The temporary unavailability of the VwbP may affect individual verification processes. It should be noted, however, that persons subject to due diligence, such as banks and trust companies, must comply with their own statutorily prescribed verification, identification, and documentation procedures.

    The unavailability of individual registers therefore does not mean that the anti-money laundering controls performed by persons subject to due diligence are suspended.

    Is this a cyberattack on the Liechtenstein financial centre?

    No. It is an attack by unknown perpetrators on the state-operated Register of Beneficial Owners of Legal Entities.

    The market participants' systems and their client data are not affected.

    Around 31,000 legal entities are affected. Is that not a massive failure?

    The scale of the incident is considerable and must not be downplayed. Precisely for this reason, full clarification, transparent communication, and effective consequences are required. The Government and the authorities responded immediately and established a crisis unit.

    For an assessment, however, the results of the ongoing investigation must be awaited. At this point in time, it would be premature to determine technical, organisational, or personal responsibilities.

    Has bank client secrecy been breached?

    No. The incident concerns data from a state register, not data held by banks in the context of their client relationships. Bank client secrecy as well as account, asset, transaction, and advisory information are not affected.

    Is data from insurance contracts affected?

    No. The incident concerns data from a state register, not data held by insurance companies in the context of their client relationships.

    Is anything known about the perpetrators or motives?

    No, there are currently no indications as to the perpetrators or the motives. The Government will not speculate about possible motives.

    How is the event to be viewed from a data protection perspective?

    It constitutes a personal data breach within the meaning of Article 33 of the General Data Protection Regulation (GDPR) – specifically, a case in which unauthorised third parties unlawfully gained access to personal data. Article 33 requires the incident to be notified to the data protection supervisory authority within 72 hours. If not all details of the incident are yet known, a preliminary notification must be submitted. This notification was made within the deadline.

    How does the Government plan to comply with the requirements of the General Data Protection Regulation (Article 34)?

    Under Article 34 of the General Data Protection Regulation (GDPR), data subjects must be informed if the breach poses a high risk to them. This possibility must clearly be assumed in the present situation. For this reason, they must be informed without undue delay. According to Recital 87, “the fact that the notification was made without undue delay should be established taking into account in particular the nature and gravity of the personal data breach and its consequences and adverse effects for the data subject”. A press conference such as the one held on the evening of 2 August 2026 counts as a first information measure under Article 34 GDPR.

    Where can those affected get in touch?

    Those affected and market participants can direct questions to vwbpfragen@llv.li or by telephone on +423 232 90 00 (on weekdays from 8 a.m. to 12 noon). The email address is managed by the Office of Justice, and expert information will be provided.

    Has a criminal complaint been filed?

    A criminal complaint has been filed, and investigation proceedings have been initiated. The Office of the Public Prosecutor has applied to the Liechtenstein Court of Justice for preliminary inquiries against unknown perpetrators on suspicion of illegal access to a computer system under §118a(1)(1) and §118a(2) of the Criminal Code (StGB) and data theft under §131a StGB.

    Have other systems been taken offline?

    Yes, two systems, the electronic VAT system (eMWST) and the electronic reporting and data exchange platform Lides, were proactively taken offline. This is a purely precautionary measure. There is no indication that an attack could have taken place on these systems.

    In addition, it was decided to proactively take the Central Register of Accounts (ZKR), the tax administration system Intax, the Terris system, and the goAML web portal of the Financial Intelligence Unit (FIU) offline as well. This, too, is a purely precautionary measure, and there is no indication of a vulnerability.

    The systems are now undergoing additional comprehensive security checks.

    Will international agreements be temporarily suspended until the security of the systems and data protection are ensured again?

    No.

    Does Liechtenstein have a fundamental problem with its cybersecurity?

    No. This serious incident must be rigorously investigated, but it does not yet permit any sweeping conclusions about the cybersecurity of an entire country. This is a criminal attack.

    What is decisive for trust is how an incident is detected, contained, clarified, and dealt with. This includes transparency, clear responsibilities, and the swift implementation of the necessary improvements.

    In this case, the attack was detected quickly, and the system was immediately taken offline as a result. The public was informed transparently. Comprehensive analyses are currently under way. The Government's top priority is to fully clarify the incident as quickly as possible, inform those affected, and initiate countermeasures.

    Can clients still trust the financial centre?

    Trust is not based on the possibility of ruling out cyber risks entirely. Trust is created by robust protection systems, clear processes, transparency, and a rigorous response to incidents.

    In this specific case, no client data on the market participants' systems was compromised. The security of client funds and services is not affected.

    Does the incident weaken the fight against money laundering in Liechtenstein?

    No. It changes nothing about the zero tolerance of Liechtenstein and its financial centre towards money laundering and terrorist financing. The rigorous investigation and remediation of the incident are part of a credible and effective integrity system.

    Will the incident damage the international reputation of the financial centre?

    The incident is highly regrettable and must not be trivialised. For long-term reputation, however, what is decisive is not merely that a cyber incident has occurred, but above all how it is handled.

    Trust requires that such an incident be clarified quickly, transparently, and completely, and that the necessary consequences be drawn from the findings. The Government takes the incident very seriously and immediately established a crisis unit, which is working urgently on clarifying it. The associations are in close contact with the authorities and the Government in this regard.

    What matters now is to maintain the existing trust through determined action and open communication.

    Footer area