- Which and how many legal entities are affected?
A total of around 31,000 legal entities are affected by the cyberattack, including entities that had already been deleted. For legal entities that are entered in the Commercial Register but for which no beneficial owners are required to be recorded in the Register of Beneficial Owners (VwbP) under the statutory requirements, no information on beneficial owners accordingly appears in the VwbP’s electronic system.
- What data is affected?
The data concerned comprises the name/designation of the legal entities and the information on the legal entities' beneficial owners, i.e. the role(s), surname, first name, date of birth, nationality (or nationalities), and country of residence of the legal entity's beneficial owners. A beneficial owner is the natural person who ultimately owns or controls the legal entity.
According to the current state of information, the data affected is that contained in the most recently completed version of the data entry in the VwbP or whose data entry had the status “In Bearbeitung” (in progress) or “In Mutation” (undergoing modification) at the time of the data protection incident.
- How many natural persons are affected?
The Office of Justice has analysed the group of persons affected by the cyberattack. For legal and investigative reasons, no information about this group of persons can be communicated.
- Is the Register of Beneficial Owners still reliable after the attack?
According to the current state of knowledge, there are no indications that data was modified or deleted. The system was taken offline as a precaution.
Before the system is brought back into operation, its integrity and security will be comprehensively reviewed. Responsibility for review lies with the competent public bodies.
- Can the business associations currently still use the VwbP to fulfil their due diligence obligations?
It is currently not possible to generate extracts directly from outside, but applications can be submitted to the Foundation and Trust Supervision and Anti-Money Laundering Division (STIFTA/GWP) of the Office of Justice, which can still access the VwbP internally.
The temporary unavailability of the VwbP may affect individual verification processes. It should be noted, however, that persons subject to due diligence, such as banks and trust companies, must comply with their own statutorily prescribed verification, identification, and documentation procedures.
The unavailability of individual registers therefore does not mean that the anti-money laundering controls performed by persons subject to due diligence are suspended.
- Is this a cyberattack on the Liechtenstein financial centre?
No. It is an attack by unknown perpetrators on the state-operated Register of Beneficial Owners of Legal Entities.
The market participants' systems and their client data are not affected.
- Around 31,000 legal entities are affected. Is that not a massive failure?
The scale of the incident is considerable and must not be downplayed. Precisely for this reason, full clarification, transparent communication, and effective consequences are required. The Government and the authorities responded immediately and established a crisis unit.
For an assessment, however, the results of the ongoing investigation must be awaited. At this point in time, it would be premature to determine technical, organisational, or personal responsibilities.
- Has bank client secrecy been breached?
No. The incident concerns data from a state register, not data held by banks in the context of their client relationships. Bank client secrecy as well as account, asset, transaction, and advisory information are not affected.
- Is data from insurance contracts affected?
No. The incident concerns data from a state register, not data held by insurance companies in the context of their client relationships.
- Is anything known about the perpetrators or motives?
No, there are currently no indications as to the perpetrators or the motives. The Government will not speculate about possible motives.
- How is the event to be viewed from a data protection perspective?
It constitutes a personal data breach within the meaning of Article 33 of the General Data Protection Regulation (GDPR) – specifically, a case in which unauthorised third parties unlawfully gained access to personal data. Article 33 requires the incident to be notified to the data protection supervisory authority within 72 hours. If not all details of the incident are yet known, a preliminary notification must be submitted. This notification was made within the deadline.
- How does the Government plan to comply with the requirements of the General Data Protection Regulation (Article 34)?
Under Article 34 of the General Data Protection Regulation (GDPR), data subjects must be informed if the breach poses a high risk to them. This possibility must clearly be assumed in the present situation. For this reason, they must be informed without undue delay. According to Recital 87, “the fact that the notification was made without undue delay should be established taking into account in particular the nature and gravity of the personal data breach and its consequences and adverse effects for the data subject”. A press conference such as the one held on the evening of 2 August 2026 counts as a first information measure under Article 34 GDPR.
- Where can those affected get in touch?
Those affected and market participants can direct questions to vwbpfragen@llv.li or by telephone on +423 232 90 00 (on weekdays from 8 a.m. to 12 noon). The email address is managed by the Office of Justice, and expert information will be provided.
- Has a criminal complaint been filed?
A criminal complaint has been filed, and investigation proceedings have been initiated. The Office of the Public Prosecutor has applied to the Liechtenstein Court of Justice for preliminary inquiries against unknown perpetrators on suspicion of illegal access to a computer system under §118a(1)(1) and §118a(2) of the Criminal Code (StGB) and data theft under §131a StGB.
- Have other systems been taken offline?
Yes, two systems, the electronic VAT system (eMWST) and the electronic reporting and data exchange platform Lides, were proactively taken offline. This is a purely precautionary measure. There is no indication that an attack could have taken place on these systems.
In addition, it was decided to proactively take the Central Register of Accounts (ZKR), the tax administration system Intax, the Terris system, and the goAML web portal of the Financial Intelligence Unit (FIU) offline as well. This, too, is a purely precautionary measure, and there is no indication of a vulnerability.
The systems are now undergoing additional comprehensive security checks.
- Will international agreements be temporarily suspended until the security of the systems and data protection are ensured again?
No.
- Does Liechtenstein have a fundamental problem with its cybersecurity?
No. This serious incident must be rigorously investigated, but it does not yet permit any sweeping conclusions about the cybersecurity of an entire country. This is a criminal attack.
What is decisive for trust is how an incident is detected, contained, clarified, and dealt with. This includes transparency, clear responsibilities, and the swift implementation of the necessary improvements.
In this case, the attack was detected quickly, and the system was immediately taken offline as a result. The public was informed transparently. Comprehensive analyses are currently under way. The Government's top priority is to fully clarify the incident as quickly as possible, inform those affected, and initiate countermeasures.
- Can clients still trust the financial centre?
Trust is not based on the possibility of ruling out cyber risks entirely. Trust is created by robust protection systems, clear processes, transparency, and a rigorous response to incidents.
In this specific case, no client data on the market participants' systems was compromised. The security of client funds and services is not affected.
- Does the incident weaken the fight against money laundering in Liechtenstein?
No. It changes nothing about the zero tolerance of Liechtenstein and its financial centre towards money laundering and terrorist financing. The rigorous investigation and remediation of the incident are part of a credible and effective integrity system.
- Will the incident damage the international reputation of the financial centre?
The incident is highly regrettable and must not be trivialised. For long-term reputation, however, what is decisive is not merely that a cyber incident has occurred, but above all how it is handled.
Trust requires that such an incident be clarified quickly, transparently, and completely, and that the necessary consequences be drawn from the findings. The Government takes the incident very seriously and immediately established a crisis unit, which is working urgently on clarifying it. The associations are in close contact with the authorities and the Government in this regard.
What matters now is to maintain the existing trust through determined action and open communication.