jump to content jump to footer

Header area

Content area

In focus  

Cyberattack on the VwbP: latest information

    What happened?

    During the night of 29/30 July 2026, unknown perpetrators gained unlawful access to the VwbP by digital means. In the course of the day on 30 July 2026, irregularities were noticed at the Office of Justice. The Office of Information Technology was subsequently contacted to analyse the situation. On the afternoon of 1 August 2026, the first confirmed results of the preliminary investigations were transmitted to the Government.

    It has been established that the perpetrators were able to gain unlawful access to the register and exfiltrate copies of data relating to around 31,000 legal entities. The VwbP contains information on the beneficial owners of legal entities. As a result of the incident, the register is not available to external users via the website www.llv.li for the time being. According to the current state of knowledge, there are no indications that data in the system was modified or deleted.

    The forensic investigations and the related analyses of how the attack unfolded and how the security barriers were circumvented are continuing. A first indication of a possible entry point of the attack has been identified. It was a targeted attack, carried out at a high technical level, on a highly complex security structure. The preliminary results also show that the VwbP was attacked specifically and in an isolated manner. According to the current state of knowledge, no unlawful access attempts were registered either on the National Administration's servers or on other National Administration systems. Nevertheless, the Government has ordered that, as a precautionary measure, further systems containing sensitive data be temporarily taken offline. These systems are undergoing further comprehensive security checks.

    What measures have been taken?

    Based on the initial suspicion, the Office of Information Technology immediately implemented measures to secure the data and took the affected system offline. At the same time, a comprehensive analysis of the incident was initiated. On 31 July 2026, the Government was informed that a potentially successful attack on the VwbP had taken place. On the afternoon of 1 August 2026, the first confirmed results of the preliminary investigations were transmitted to the Government.

    On Friday, 31 July 2026, the eMWST portal for value added tax and the electronic reporting and data exchange platform Lides had already been taken offline. On Monday, 3 August 2026, the Central Register of Accounts and the central tax administration system Intax followed. These are purely precautionary measures. There is no indication that unlawful access took place in these systems. All systems are now undergoing additional comprehensive security checks.

    Over the weekend, the Office of Justice filed a criminal complaint against persons unknown. The prosecution authorities then immediately took up their investigations. Digital traces are being analysed and followed up in cooperation with European authorities.

    Information for those affected

    The incident is being treated as a personal data breach under the GDPR. Data subjects are being informed as quickly as possible. 

    In addition, an information point has been set up as a further channel for questions and information for those affected. It is available starting Tuesday, 4 August 2026, at 4 p.m. by telephone at +423 232 90 00 or by email at vwbpfragen@llv.li. The information point can be reached by telephone on weekdays from 8 a.m. to 12 noon.

    What is the VwbP?

    The Register of Beneficial Owners (VwbP) was introduced in Liechtenstein to implement the European anti-money laundering directives. The Act on the Register of Beneficial Owners of Domestic Legal Entities (VwEG) first entered into force in 2019, implementing the requirements of the 4th EU Anti-Money Laundering Directive. The aim is to strengthen the fight against money laundering, terrorist financing, and related offences.

    The 5th EU Anti-Money Laundering Directive expanded the requirements for the register. These include, in particular, greater transparency, additional obligations to report discrepancies, extended rights of inspection, and stronger supervision and control. In addition, the previous distinction between the German terms “wirtschaftlicher Eigentümer” and “wirtschaftlich berechtigte Person” (both “beneficial owner” in English) was abolished and the terminology aligned with the due diligence legislation.

    The current register contains information on the beneficial owners of legal entities and serves the competent authorities and certain obliged entities as an important instrument for preventing money laundering and terrorist financing.

    The register contains data on the beneficial owners of legal entities. Legal entities include companies, foundations, and trusts. It records the name of the structure as well as the surname, first name, date of birth, nationality, and country of residence of the structure’s beneficial owners.

    The Act on the Register of the Beneficial Owners of Legal Entities (VwbPG) entered into force in 2021.

    Data protection

    The attack on the VwbP constitutes a personal data breach within the meaning of Article 33 of the General Data Protection Regulation (GDPR). The crisis unit is working urgently to ensure that the data subjects are informed of the breach of the protection of their data as quickly as possible in accordance with Article 34 GDPR.

    However, since not all contact details – for example, residential addresses – are stored in the register, the legal entities are now being informed of the incident and asked to inform the affected data subjects. As a result, no further data going beyond the Anti-Money Laundering Directive will flow to governmental bodies.

    News

    FAQ

    • A total of around 31,000 legal entities are affected by the cyberattack, including entities that had already been deleted. For legal entities that are entered in the Commercial Register but for which no beneficial owners are required to be recorded in the Register of Beneficial Owners (VwbP) under the statutory requirements, no information on beneficial owners accordingly appears in the VwbP’s electronic system.

    • The data concerned comprises the names/designations of the legal entities and the information on the legal entities' beneficial owners. That is: the role, surname, first name, date of birth, nationality (or nationalities), and country of residence of the legal entity's beneficial owners. Addresses and telephone numbers are not recorded in the VwbP's electronic system. Nor does it record data on the financial situation of the legal entities, such as revenues, assets, amounts of distributions, dividends, etc.

      A beneficial owner is the natural person who ultimately owns or controls the legal entity.

    • At this point in time, no figure can be given for the number of natural persons affected.

    • According to the current state of knowledge, there are no indications that data was modified or deleted. The system was taken offline as a precaution.

      Before the system is brought back into operation, its integrity and security will be comprehensively reviewed.

    • It is currently not possible to generate extracts directly from outside, but applications can be submitted to the Foundation Supervision and Anti-Money Laundering Division (STIFA/GWP) of the Office of Justice, which can still access the VwbP internally.

      The unavailability of individual registers therefore does not mean that the anti-money laundering controls performed by persons subject to due diligence are suspended.

    • No. It is an attack by unknown perpetrators on the state-operated Register of Beneficial Owners of Legal Entities.

      The market participants' systems and their client data are not affected.

    • The scale of the incident is considerable and must not be downplayed. Precisely for this reason, full clarification, transparent communication, and effective consequences are required. The Government and the authorities responded immediately and established a crisis unit.

    • No. The incident concerns data from a state register, not data held by banks in the context of their client relationships. Bank client secrecy as well as account, asset, transaction, and advisory information are not affected.

    • No. The incident concerns data from a state register, not data held by insurance companies in the context of their client relationships.

    • No, there are currently no indications as to the perpetrators or the motives. The Government will not speculate about possible motives.

    • It constitutes a personal data breach within the meaning of Article 33 of the General Data Protection Regulation (GDPR) – specifically, a case in which unauthorised third parties unlawfully gained access to personal data. Article 33 requires the incident to be notified to the data protection supervisory authority within 72 hours. If not all details of the incident are yet known, a preliminary notification must be submitted. This notification was made within the deadline.

    • Under Article 34 of the General Data Protection Regulation (GDPR), data subjects must be informed if the breach poses a high risk to them. This possibility must clearly be assumed in the present situation. For this reason, they must be informed without undue delay. According to Recital 87, “the fact that the notification was made without undue delay should be established taking into account in particular the nature and gravity of the personal data breach and its consequences and adverse effects for the data subject”.

    • Those affected and market participants can direct questions to vwbpfragen@llv.li. The email address is managed by the Office of Justice.

      A hotline (+423 232 90 00) is set up for data subjects, available for the first time on Tuesday, 4 August 2026, from 4 p.m. to 7 p.m. and on the following days from 8 a.m. to 12 noon.

    • A criminal complaint has been filed, and investigation proceedings have been initiated.

    • Yes, two systems, the electronic VAT system (eMWST) and the electronic reporting and data exchange platform Lides, were proactively taken offline. This is a purely precautionary measure. There is no indication that an attack could have taken place on these systems.

      In addition, it was decided to proactively take the Central Register of Accounts (ZKR) and the tax administration system Intax offline as well. This, too, is a purely precautionary measure, and there is no indication of a vulnerability.

      The systems are now undergoing additional comprehensive security checks.

    • No.

    • No. This serious incident must be rigorously investigated, but it does not yet permit any sweeping conclusions about the cybersecurity of an entire country.

      What is decisive for trust is how an incident is detected, contained, clarified, and dealt with. This includes transparency, clear responsibilities, and the swift implementation of the necessary improvements.

      In this case, the attack was detected quickly, and the system was immediately taken offline as a result. The public was informed transparently. Comprehensive analyses are currently under way. The top priority is to clarify the incident in full as quickly as possible, inform those affected, and initiate countermeasures.

    • Yes. Trust is created by personal contacts, robust protection systems, clear processes, transparency, and a rigorous response to incidents.

      Moreover, in this specific case, no client data on the market participants' systems was compromised. The security of client funds and services is not affected.

    • No. It changes nothing about the zero tolerance of Liechtenstein and its financial centre towards money laundering and terrorist financing. The rigorous investigation and remediation of the incident are part of a credible and effective integrity system.

    • The incident is highly regrettable and must not be trivialised. For long-term reputation, however, what is decisive is not merely that a cyber incident has occurred, but above all how it is handled.

      Trust requires that such an incident be clarified quickly, transparently, and completely, and that the necessary consequences be drawn from the findings. The Government takes the incident very seriously and immediately established a crisis unit, which is working urgently on clarifying it. The associations are in close contact with the authorities and the Government in this regard.

    Which and how many legal entities are affected?

    A total of around 31,000 legal entities are affected by the cyberattack, including entities that had already been deleted. For legal entities that are entered in the Commercial Register but for which no beneficial owners are required to be recorded in the Register of Beneficial Owners (VwbP) under the statutory requirements, no information on beneficial owners accordingly appears in the VwbP’s electronic system.

    What data is affected?

    The data concerned comprises the names/designations of the legal entities and the information on the legal entities' beneficial owners. That is: the role, surname, first name, date of birth, nationality (or nationalities), and country of residence of the legal entity's beneficial owners. Addresses and telephone numbers are not recorded in the VwbP's electronic system. Nor does it record data on the financial situation of the legal entities, such as revenues, assets, amounts of distributions, dividends, etc.

    A beneficial owner is the natural person who ultimately owns or controls the legal entity.

    How many natural persons are affected?

    At this point in time, no figure can be given for the number of natural persons affected.

    Is the Register of Beneficial Owners still reliable after the attack?

    According to the current state of knowledge, there are no indications that data was modified or deleted. The system was taken offline as a precaution.

    Before the system is brought back into operation, its integrity and security will be comprehensively reviewed.

    Can the business associations currently still use the VwbP to fulfil their due diligence obligations?

    It is currently not possible to generate extracts directly from outside, but applications can be submitted to the Foundation Supervision and Anti-Money Laundering Division (STIFA/GWP) of the Office of Justice, which can still access the VwbP internally.

    The unavailability of individual registers therefore does not mean that the anti-money laundering controls performed by persons subject to due diligence are suspended.

    Is this a cyberattack on the Liechtenstein financial centre?

    No. It is an attack by unknown perpetrators on the state-operated Register of Beneficial Owners of Legal Entities.

    The market participants' systems and their client data are not affected.

    Around 31,000 legal entities are affected. Is that not a massive failure?

    The scale of the incident is considerable and must not be downplayed. Precisely for this reason, full clarification, transparent communication, and effective consequences are required. The Government and the authorities responded immediately and established a crisis unit.

    Has bank client secrecy been breached?

    No. The incident concerns data from a state register, not data held by banks in the context of their client relationships. Bank client secrecy as well as account, asset, transaction, and advisory information are not affected.

    Is data from insurance contracts affected?

    No. The incident concerns data from a state register, not data held by insurance companies in the context of their client relationships.

    Is anything known about the perpetrators or motives?

    No, there are currently no indications as to the perpetrators or the motives. The Government will not speculate about possible motives.

    How is the event to be viewed from a data protection perspective?

    It constitutes a personal data breach within the meaning of Article 33 of the General Data Protection Regulation (GDPR) – specifically, a case in which unauthorised third parties unlawfully gained access to personal data. Article 33 requires the incident to be notified to the data protection supervisory authority within 72 hours. If not all details of the incident are yet known, a preliminary notification must be submitted. This notification was made within the deadline.

    How does the Government plan to comply with the requirements of the General Data Protection Regulation (Article 34)?

    Under Article 34 of the General Data Protection Regulation (GDPR), data subjects must be informed if the breach poses a high risk to them. This possibility must clearly be assumed in the present situation. For this reason, they must be informed without undue delay. According to Recital 87, “the fact that the notification was made without undue delay should be established taking into account in particular the nature and gravity of the personal data breach and its consequences and adverse effects for the data subject”.

    Where can those affected get in touch with questions?

    Those affected and market participants can direct questions to vwbpfragen@llv.li. The email address is managed by the Office of Justice.

    A hotline (+423 232 90 00) is set up for data subjects, available for the first time on Tuesday, 4 August 2026, from 4 p.m. to 7 p.m. and on the following days from 8 a.m. to 12 noon.

    Has a criminal complaint been filed?

    A criminal complaint has been filed, and investigation proceedings have been initiated.

    Have other systems been taken offline?

    Yes, two systems, the electronic VAT system (eMWST) and the electronic reporting and data exchange platform Lides, were proactively taken offline. This is a purely precautionary measure. There is no indication that an attack could have taken place on these systems.

    In addition, it was decided to proactively take the Central Register of Accounts (ZKR) and the tax administration system Intax offline as well. This, too, is a purely precautionary measure, and there is no indication of a vulnerability.

    The systems are now undergoing additional comprehensive security checks.

    Will international agreements be temporarily suspended until the security of the systems and data protection are ensured again?

    No.

    Does Liechtenstein have a fundamental problem with its cybersecurity?

    No. This serious incident must be rigorously investigated, but it does not yet permit any sweeping conclusions about the cybersecurity of an entire country.

    What is decisive for trust is how an incident is detected, contained, clarified, and dealt with. This includes transparency, clear responsibilities, and the swift implementation of the necessary improvements.

    In this case, the attack was detected quickly, and the system was immediately taken offline as a result. The public was informed transparently. Comprehensive analyses are currently under way. The top priority is to clarify the incident in full as quickly as possible, inform those affected, and initiate countermeasures.

    Can clients still trust the financial centre?

    Yes. Trust is created by personal contacts, robust protection systems, clear processes, transparency, and a rigorous response to incidents.

    Moreover, in this specific case, no client data on the market participants' systems was compromised. The security of client funds and services is not affected.

    Does the incident weaken the fight against money laundering in Liechtenstein?

    No. It changes nothing about the zero tolerance of Liechtenstein and its financial centre towards money laundering and terrorist financing. The rigorous investigation and remediation of the incident are part of a credible and effective integrity system.

    Will the incident damage the international reputation of the financial centre?

    The incident is highly regrettable and must not be trivialised. For long-term reputation, however, what is decisive is not merely that a cyber incident has occurred, but above all how it is handled.

    Trust requires that such an incident be clarified quickly, transparently, and completely, and that the necessary consequences be drawn from the findings. The Government takes the incident very seriously and immediately established a crisis unit, which is working urgently on clarifying it. The associations are in close contact with the authorities and the Government in this regard.

    Footer area