What measures have been taken?
Based on the initial suspicion, the Office of Information Technology immediately implemented measures to secure the data and took the affected system offline. At the same time, a comprehensive analysis of the incident was initiated. On 31 July 2026, the Government was informed that a potentially successful attack on the VwbP had taken place. On the afternoon of 1 August 2026, the first confirmed results of the preliminary investigations were transmitted to the Government.
Following the criminal attack on the Register of Beneficial Owners (VwbP), four state systems were taken offline as a precautionary measure in order to subject them to additional security checks. On 5 August, the crisis unit decided to review further systems and to take them offline temporarily for this purpose.
The National Cyber Security Unit is in contact with the operators of critical infrastructures in order to assess the situation on an ongoing basis. The National Cyber Security Unit's inquiries to date give no indication that critical infrastructures are affected. Meanwhile, the prosecution authorities' investigations to find the perpetrators are proceeding urgently.