Thu 20 Aug 2026 / 18:01 ET
Kernel
Security 3 min read

Liechtenstein beneficial owners breach exposes data tied to 31,000 entities

Liechtenstein says attackers copied data tied to about 31,000 legal entities from its beneficial-ownership register.

Mara Chen-Doyle

By Mara Chen-Doyle / Staff Writer

Liechtenstein beneficial owners breach exposes data tied to 31,000 entities
img: The Record

Liechtenstein says a Liechtenstein beneficial owners breach allowed unknown attackers to copy data tied to roughly 31,000 legal entities from the country’s Register of Beneficial Owners. The government said the unauthorized digital access occurred during the night of July 29 to July 30, and that the affected system was taken offline after officials spotted irregularities on July 30.

The number needs careful handling. Government officials reported copies of data relating to about 31,000 legal entities, while some outside reports described the figure as people or records. The official notice does not establish that 31,000 distinct individuals were affected, nor does it list every data field that was taken.

The Office of Justice detected the irregularities and contacted Liechtenstein’s Office of Information Technology, according to the government’s August 3 statement. The IT office moved to secure the data, disconnected the affected system and began an incident analysis. The government was told on July 31 that the attack may have succeeded; it received the first confirmed preliminary findings on August 1.

Officials said they had no indication that information remaining in the system had been altered or deleted. The register was unavailable to external users through the llv.li website when the government published its statement.

What is Liechtenstein’s Register of Beneficial Owners?

The register holds beneficial-owner information for legal entities, including companies, foundations and trusts. A beneficial owner is the person behind an entity, rather than merely the entity’s formal name. The government says the database is maintained to support efforts against money laundering and terrorist financing.

Its governing law took effect in 2021 to implement requirements from the European Union’s fifth Anti-Money Laundering Directive, the government said. That purpose explains why the database links legal structures to the people identified as their beneficial owners. It does not, however, answer which information within the copied data is now in the attackers’ hands.

What has the government done after the breach?

The government convened a crisis unit on the evening of August 1 and formally confirmed it the next day. Prime Minister Brigitte Haas and Justice Minister Emanuel Schädler lead the group, which has been tasked with investigating the incident, notifying affected people and organizing countermeasures.

Liechtenstein classified the event as a personal-data breach under Article 33 of the EU General Data Protection Regulation. It said it was working to notify affected data subjects under Article 34 and was setting up a central contact point. People with questions can email [email protected].

The government identified the perpetrators only as unknown and said its investigation was ongoing. Its announcement did not identify an attack method, a responsible group, a motive, a ransom demand or whether the copied data had been published.

This story draws on original reporting from The Record.

More Security/

view all ↗