The Register of Beneficial Owners (VwbP) has been the target of a cyberattack. Copies of data relating to around 31,000 legal entities were unlawfully exfiltrated. The Government has convened a crisis unit.

According to preliminary findings, unknown perpetrators gained unlawful access to the VwbP by digital means during the night of 29/30 July 2026. In the course of the day on 30 July 2026, irregularities were noticed at the Office of Justice. The Office of Information Technology was subsequently contacted to analyse the situation. Based on the initial suspicion, the Office of Information Technology immediately implemented measures to secure the data and took the affected system offline. At the same time, a comprehensive analysis of the incident was initiated. On 31 July 2026, the Government was informed that a potentially successful attack on the VwbP had taken place. On the afternoon of 1 August 2026, the first confirmed results of the preliminary investigations were transmitted to the Government.

It has since been established that the perpetrators were able to gain unlawful access to the register and exfiltrate copies of data relating to around 31,000 legal entities. The VwbP contains information on the beneficial owners of legal entities. As a result of the incident, the register is not available to external users via the llv.li website for the time being. According to the current state of knowledge, there are no indications that data in the system was modified or deleted.

Crisis unit established over the weekend

The Government convened a crisis unit on the evening of 1 August 2026, which began its work immediately, and formally confirmed it on 2 August 2026. The crisis unit is headed by Prime Minister Brigitte Haas and Minister of Justice Emanuel Schädler. The top priority is to fully clarify the incident as quickly as possible, inform those affected, and initiate countermeasures. The crisis unit will provide information on the latest developments on Monday, 3 August 2026.

Breach of data protection

The attack on the VwbP constitutes a personal data breach within the meaning of Article 33 of the General Data Protection Regulation (GDPR). The crisis unit is working urgently to ensure that the data subjects are informed of the breach of the protection of their data as quickly as possible in accordance with Article 34 GDPR. At the same time, a central information point is being set up where affected persons can direct any questions. Enquiries can be submitted by email to vwbpfragen@llv.li.

The Register of Beneficial Owners

The VwbP is maintained for the purpose of preventing money laundering and terrorist financing. It contains data on the beneficial owners of legal entities. Legal entities include companies, foundations, and trusts. The Act on the Register of the Beneficial Owners of Legal Entities (VwbPG) entered into force in 2021, implementing the requirements of the 5th EU Anti-Money Laundering Directive.