- Which and how many legal entities are affected?
A total of around 31,000 legal entities are affected by the cyberattack, including entities that had already been deleted. For legal entities that are entered in the Commercial Register but for which no beneficial owners are required to be recorded in the Register of Beneficial Owners (VwbP) under the statutory requirements, no information on beneficial owners accordingly appears in the VwbP’s electronic system.
- What data is affected?
The data concerned comprises the names/designations of the legal entities and the information on the legal entities' beneficial owners. That is: the role, surname, first name, date of birth, nationality (or nationalities), and country of residence of the legal entity's beneficial owners. Addresses and telephone numbers are not recorded in the VwbP's electronic system. Nor does it record data on the financial situation of the legal entities, such as revenues, assets, amounts of distributions, dividends, etc.
A beneficial owner is the natural person who ultimately owns or controls the legal entity.
- How many natural persons are affected?
At this point in time, no figure can be given for the number of natural persons affected.
- Is the Register of Beneficial Owners still reliable after the attack?
According to the current state of knowledge, there are no indications that data was modified or deleted. The system was taken offline as a precaution.
Before the system is brought back into operation, its integrity and security will be comprehensively reviewed.
- Can the business associations currently still use the VwbP to fulfil their due diligence obligations?
It is currently not possible to generate extracts directly from outside, but applications can be submitted to the Foundation Supervision and Anti-Money Laundering Division (STIFA/GWP) of the Office of Justice, which can still access the VwbP internally.
The unavailability of individual registers therefore does not mean that the anti-money laundering controls performed by persons subject to due diligence are suspended.
- Is this a cyberattack on the Liechtenstein financial centre?
No. It is an attack by unknown perpetrators on the state-operated Register of Beneficial Owners of Legal Entities.
The market participants' systems and their client data are not affected.
- Around 31,000 legal entities are affected. Is that not a massive failure?
The scale of the incident is considerable and must not be downplayed. Precisely for this reason, full clarification, transparent communication, and effective consequences are required. The Government and the authorities responded immediately and established a crisis unit.
- Has bank client secrecy been breached?
No. The incident concerns data from a state register, not data held by banks in the context of their client relationships. Bank client secrecy as well as account, asset, transaction, and advisory information are not affected.
- Is data from insurance contracts affected?
No. The incident concerns data from a state register, not data held by insurance companies in the context of their client relationships.
- Is anything known about the perpetrators or motives?
No, there are currently no indications as to the perpetrators or the motives. The Government will not speculate about possible motives.
- How is the event to be viewed from a data protection perspective?
It constitutes a personal data breach within the meaning of Article 33 of the General Data Protection Regulation (GDPR) – specifically, a case in which unauthorised third parties unlawfully gained access to personal data. Article 33 requires the incident to be notified to the data protection supervisory authority within 72 hours. If not all details of the incident are yet known, a preliminary notification must be submitted. This notification was made within the deadline.
- How does the Government plan to comply with the requirements of the General Data Protection Regulation (Article 34)?
Under Article 34 of the General Data Protection Regulation (GDPR), data subjects must be informed if the breach poses a high risk to them. This possibility must clearly be assumed in the present situation. For this reason, they must be informed without undue delay. According to Recital 87, “the fact that the notification was made without undue delay should be established taking into account in particular the nature and gravity of the personal data breach and its consequences and adverse effects for the data subject”.
- Where can those affected get in touch with questions?
Those affected and market participants can direct questions to vwbpfragen@llv.li. The email address is managed by the Office of Justice.
A hotline (+423 232 90 00) is set up for data subjects, available for the first time on Tuesday, 4 August 2026, from 4 p.m. to 7 p.m. and on the following days from 8 a.m. to 12 noon.
- Has a criminal complaint been filed?
A criminal complaint has been filed, and investigation proceedings have been initiated.
- Have other systems been taken offline?
Yes, two systems, the electronic VAT system (eMWST) and the electronic reporting and data exchange platform Lides, were proactively taken offline. This is a purely precautionary measure. There is no indication that an attack could have taken place on these systems.
In addition, it was decided to proactively take the Central Register of Accounts (ZKR) and the tax administration system Intax offline as well. This, too, is a purely precautionary measure, and there is no indication of a vulnerability.
The systems are now undergoing additional comprehensive security checks.
- Will international agreements be temporarily suspended until the security of the systems and data protection are ensured again?
No.
- Does Liechtenstein have a fundamental problem with its cybersecurity?
No. This serious incident must be rigorously investigated, but it does not yet permit any sweeping conclusions about the cybersecurity of an entire country.
What is decisive for trust is how an incident is detected, contained, clarified, and dealt with. This includes transparency, clear responsibilities, and the swift implementation of the necessary improvements.
In this case, the attack was detected quickly, and the system was immediately taken offline as a result. The public was informed transparently. Comprehensive analyses are currently under way. The top priority is to clarify the incident in full as quickly as possible, inform those affected, and initiate countermeasures.
- Can clients still trust the financial centre?
Yes. Trust is created by personal contacts, robust protection systems, clear processes, transparency, and a rigorous response to incidents.
Moreover, in this specific case, no client data on the market participants' systems was compromised. The security of client funds and services is not affected.
- Does the incident weaken the fight against money laundering in Liechtenstein?
No. It changes nothing about the zero tolerance of Liechtenstein and its financial centre towards money laundering and terrorist financing. The rigorous investigation and remediation of the incident are part of a credible and effective integrity system.
- Will the incident damage the international reputation of the financial centre?
The incident is highly regrettable and must not be trivialised. For long-term reputation, however, what is decisive is not merely that a cyber incident has occurred, but above all how it is handled.
Trust requires that such an incident be clarified quickly, transparently, and completely, and that the necessary consequences be drawn from the findings. The Government takes the incident very seriously and immediately established a crisis unit, which is working urgently on clarifying it. The associations are in close contact with the authorities and the Government in this regard.