Article

Liechtenstein’s Anti-Money-Laundering Register Hacked: 31,000 Legal Entities Exposed, and the Database Was Never Public

Aug 3, 2026 | 24 min | cybersecurity
Language
EN DE
Open metal archive drawer with register files and redacted papers under harsh light

Overnight into July 30, 2026, unknown attackers copied data on roughly 31,000 legal entities out of Liechtenstein’s register of beneficial owners, a database that was never generally open to the public and whose entries reached third parties only through a statutory application procedure. The incident dismantles the most soothing formula of recent years, the one holding that a register closed to the public is secure enough by definition. It also shows that the legislature itself wrote the dangers to the people concerned into the statute back in 2021, and it is a reminder that a date of birth cannot be swapped out the way a password can.

I was on the autobahn, driving back from a client appointment, when my phone pushed through a message from colleagues. 2 lines, one link, nothing else. I read the report at the next rest stop and then stared at the parking lot for a while, because at that point I had barely slept in 3 days. 2 of our most important server systems had been under sustained attack, and I had spent the weekend fending those attacks off and afterward rebuilding every security strategy we run in house. Then this message arrived, with the force of a bad joke you wrote yourself.

The facts are quickly told and still larger than they look at first glance. According to the government of the principality, an unknown perpetrator gained unlawful digital access to the register of beneficial owners, abbreviated VwbP, overnight into July 30, 2026, and copied data on roughly 31,000 legal entities. Legal entities in this context means companies, foundations, and trust arrangements. More than one natural person can sit behind any single one of them, and one person can sit behind several of them, which is why nobody can responsibly state how many human beings are affected. For scale, Liechtenstein counted 41,398 residents on December 31, 2024, permanent and non-permanent population combined. The 2 figures do not measure the same thing and must not be conflated, but the ratio says something about the density of this financial center.

The thesis of this article fits into a single sentence, and it sits up here on purpose rather than at the end. The protection of a mandatory state register does not depend on who is permitted to look inside, it depends solely on who gets inside. Everything that follows explains why that is true and why we have known it for years.

The Timeline of a Night Nobody Noticed

The sequence is documented in the government’s press statement, and it deserves a careful reading, because timelines like this one contain more than any commentary does. The intrusion took place overnight into July 30, 2026. Over the course of that same day, irregularities were noticed at the Office of Justice, and the Landesspiegel adds the detail that a staff member spotted them during a routine check. The Office of Information Technology was then brought in, implemented measures to secure the data, and took the affected system off the network.

The government of the principality was informed only on July 31, 2026, that a potentially successful attack had taken place. The first confirmed findings of the preliminary investigation arrived on the afternoon of August 1, and that same evening the government convened a crisis unit, formally confirmed on August 2, 2026. Prime Minister Brigitte Haas and Minister of Justice Emanuel Schädler took the lead. The crisis unit announced that it would report on further developments in a separate statement on Monday, August 3, 2026.

That leaves a good 2 days between the intrusion and the confirmed finding, and 3 days between the intrusion and public disclosure. For an administration forced to react across a weekend, that is fast. For an attacker who pulls a copy and then needs nothing but bandwidth, it is an eternity.

What strikes me about this chain is not the response after discovery, which was remarkably fast for a public administration. What strikes me is that a human being stands at the beginning of the disclosure chain published so far. Whether technical anomaly detection was running in the background, whether it also fired, or whether it reported nothing at all is not publicly known. I am not belittling the staff member, quite the opposite, this woman probably saved days. Should it turn out that the intrusion was in fact caught only by a manual check, that would be the real finding about technical attack detection.

The second point buried in this timeline concerns the order of notification. The specialist authority learns first that something is wrong, then the technical office, then the government, then the public, and dead last come the people whose data sits in the register. That ordering is organizationally understandable and the worst conceivable one for the person affected, because they know nothing during exactly the phase in which a warning would still do them some good.

No ransom has been demanded so far, according to statements out of Vaduz, and the data has not surfaced on the darknet. Both sound like reassurance and are the precise opposite. Extortionists announce themselves early, because the threat is the entire business model. Whoever stays silent may have any number of reasons, and not one of them is currently established: espionage, a buyer, a client, collection for later exploitation, or an extortion attempt that simply has not started yet. Prime Minister Brigitte Haas summed it up at the press conference with the words „Es gibt bislang weder Lösegeldforderungen“, meaning that no ransom demands have come in so far, and she added that the register had neither surfaced on the darknet nor been offered for sale. The calm scenario stays the uglier one all the same, because it postpones any assessment of the damage indefinitely.

What This Register Actually Holds

Here it pays to read the statute instead of the press release. The act governing the register of beneficial owners of legal entities entered into force on April 1, 2021, and implements the requirements of the EU anti-money-laundering directive concerning the register of beneficial owners. Its Article 4 paragraph 1 letter a specifies what has to be collected on natural persons and reported to the Office of Justice: surname, given name, date of birth, country of residence, and nationality. According to the reports from the press conference, surname, given name, date of birth, and nationality were affected at a minimum. Martin Alge, head of the Office of Justice, additionally named the country of residence when speaking to Swiss public broadcasting. A conclusive list of fields does not appear in the government’s written statement so far.

This reads harmlessly as long as you regard it as a row in a table. Regarded as a forensic record it is something else, because that combination is the key that unlocks other holdings. A name on its own is ambiguous, a name together with a date of birth almost never is. That is exactly why the pairing of name and date of birth serves as the anchor in practically every record-linkage procedure, the point at which data from separate sources gets merged. Anyone holding this combination and laying it against an older leak turns 2 thin holdings into one fat one.

The statute even acknowledges this permanence in one place, in a way I had to read twice. Article 12 paragraph 5 requires personal data to be deleted 5 years after a legal entity ends. Article 12 paragraph 6 requires every single processing operation in the register to be logged, and paragraph 7 provides that these log records be retained for 10 years. The 2 periods run from different triggering events, so no flat gap of 5 years follows from them. What does follow is an unusually long retention of the processing trail, which makes perfect sense from a data-protection supervision standpoint and reads like a comment on priorities from the standpoint of the person in the file. A properly kept log is incidentally the reason Vaduz can say within days what happened at all.

Now comes the part that concerns everyone who has ever changed a password. A password is a temporary secret, replaceable in a matter of moments, and the old value is worthless afterward. A date of birth cannot be replaced. Neither can a nationality, a country of residence only by moving, a name only through a procedure most people will never go through. What flowed out here stays valid for the remainder of a life, and it stays valid above all for the follow-on crimes it happens to suit.

Never Public, and Gone All the Same

The second half of the headline is a finding from the statutory text rather than a flourish. The VwbP is not a public register that anyone may inspect, and it never was one. Article 13 grants selected domestic authorities a direct query procedure, specifically the Financial Intelligence Unit, the Financial Market Authority, the national police, the tax administration, the public prosecutor, the court of justice, and the bar association. Banks and financial institutions receive data under Article 15 only on application, domestic obliged entities under Article 16 likewise only on application. Third parties must under Article 17 demonstrate a legitimate interest depending on the constellation, and a dedicated commission decides on part of those applications.

Measured against what the European Union originally wanted, that is a narrow and carefully built access regime. It ended up helping exactly nothing. The perpetrators filed no application, demonstrated no legitimate interest, and convinced no commission, they used a technical weakness, and after that the entire access regime was a footnote.

This is precisely where an argument collapses that has been served as a sedative in every debate about state data collection for years now. It runs, in substance and in many variations: „The register is not public, only authorized parties can look inside“ That statement describes a legal order and says nothing whatsoever about technical reality. Access rules describe who is permitted to look. They do not describe who gets in. The whole incident lives in the gap between those 2 sentences.

The word entity is a precise term, legally clean, spelled out down to the last corporate form in Annex 1 and Annex 2 of the act. It is also a word that makes people disappear reliably. When a report says data copies on 31,000 legal entities were taken, the reader hears a number about companies, and what the reader does not hear is that behind each of those companies stands at least one human being with a date of birth. Administrative language is not obfuscation, it is precise, yet it generates distance where concern belongs. I have made a habit in expert reports of writing in parentheses behind every such figure what it actually refers to. It costs almost no effort and completely changes how a finding gets read.

I have heard that sedative formula often, in proceedings, in committees, in conversations with people who ought to know better. It is seductive because it is true and irrelevant at the same time. A vault with an excellent access policy whose back wall is made of plywood is a plywood box holding paperwork.

The Sentence the Legislature Wrote In Itself

Here comes the part that actually made me stop for a moment while reading the statute. Article 18 of the act allows a legal entity to have disclosure restricted toward obliged entities and third parties. Paragraph 2 letter a states the condition: where disclosure would expose the beneficial owner to a disproportionate risk of fraud, kidnapping, blackmail, extortion, harassment, violence, or intimidation.

That enumeration is not the invention of an excitable commentator, it has been in force since 2021. The legislature therefore knew what can happen once these records leave the protected space. It knew, it named it, it even arranged the horrors in a sequence, and it built an exemption for the orderly case out of that knowledge. For the disorderly case, meaning theft, the exemption helps nobody. Whoever obtained a restriction on disclosure was thereby protected toward domestic obliged entities under Article 16 and toward third parties under Article 17. Banks and financial institutions under Article 15 are expressly not covered by that restriction, and against an attacker it does nothing whatsoever.

For completeness a second provision belongs beside it. Article 12 paragraph 4 requires the information and personal data to be protected against unauthorized or unlawful processing through appropriate technical and organizational measures. I am not evaluating that norm here, which is a matter for the supervisory authority and possibly the courts, and I cannot judge the adequacy of the measures deployed from the outside. I am simply placing the text next to the event and leaving the rest to the reader.

Luxembourg Already Ruled on This in 2022

Anyone who thinks this realization is new has slept through the past several years. The Court of Justice of the European Union declared on November 22, 2022, in joined cases C-37/20 and C-601/20 that the provision of the anti-money-laundering directive requiring beneficial ownership information to be accessible in all cases to any member of the general public is invalid. The Grand Chamber classified public access as a serious interference with Articles 7 and 8 of the Charter of Fundamental Rights.

One passage of the reasoning is decisive for our purposes. The Court held that publication makes any later misuse worse, because records handed to the general public can be looked up at will, stored away, and passed along. That is the legal formulation of exactly the physical circumstance every technician knows. A copy is a copy, and a holding that has once gone out does not come back, because retrieving knowledge is not an operation that exists.

The Court wrote that sentence about public inspection rather than about a theft. For the outcome that makes no difference. Whether 31,000 records flow out through a web form the directive mandates or through a hole nobody mandated, the situation is identical for the person in the file. The legal order distinguishes sharply here, reality does not distinguish at all.

Why This Is Personal, and Why the Relief Was Short

My first question in that parking lot was the obvious and fairly selfish one: is my own data in there? The answer is no, and I am writing that down here even though it lowers the drama. The VwbP covers the beneficial owners of Liechtenstein legal entities together with certain trust constructions administered domestically or connected to the country. Anyone without such a structure is not in the file. The relief did not last long, then the second thought arrived, and that one is the real one.

I live with an information block under Section 51 of the German Federal Registration Act. The provision allows for it where facts justify the assumption that a register disclosure could create a danger to life, health, personal freedom, or comparable protected interests, and the statute expressly names protection against threats and unauthorized stalking, while also directing attention to whether someone belongs to a group exposed to heightened hostility because of their professional activity. My mail goes to a delivery address, my residential address appears nowhere, and that is not an eccentricity but a consequence of what I dealt with for decades.

The point is not that I am affected in Vaduz. The point is that I appear in dozens of other mandatory registers, as every one of us does, and that no information block whatsoever operates in those other registers. A block in the residents register is a block in the residents register. It stops a registration authority from handing out my address, and it stops nobody from copying an entirely different database in which I am recorded for an entirely different statutory reason. We have built a system in which the individual can steer their visibility at exactly one point, while the state generates that visibility in countless other places.

There is a further detail sitting in the statutory text that almost nobody reads. The information block under the Federal Registration Act is limited to 2 years and can be extended on application or by the authority itself. Anyone who wants to stay protected permanently therefore depends on an administrative decision taken over and over again, while other mandatory registers run on under their own and in part considerably longer retention rules. The expiry of a residents-register block says nothing about whether the same person remains stored in other registers, and the person the block was meant to hold off may by then have entirely different sources.

So what interests me about Vaduz is not Vaduz. What interests me is the construction method, and the construction method is identical everywhere.

The Vendor Nobody Names

One detail from the reporting stuck with me, because it could have come out of my own week. As a precaution, 2 further portals from the same vendor were taken off the network, of which only the value-added tax portal is in active use, and there, according to the head of the Office of Information Technology, no indications of any data outflow turned up. The name of that vendor appears in none of the reports I have read.

This is the supply chain, and it is the blind spot in almost every security assessment. An authority buys a portal solution, a company buys a module, a practice buys a booking system, and all 3 believe they have bought a product. What they bought is a dependency. If the vendor carries a weakness in its core, every customer carries it simultaneously without knowing, and the number of affected systems scales not with the diligence of the attackers but with the vendor’s customer list.

Over that weekend, since I was awake anyway, I looked at 15 systems belonging to friends and clients, in every case with explicit written consent. 8 of them were already compromised, server and website alike. Not at risk, not theoretically vulnerable, but open for some time. That figure is not a study and not a representative sample, it is a snapshot from a single weekend, and I am expressly not selling it here as a statistic. As a finding it is enough for me.

Why this is escalating right now is something I worked through in 2 recent pieces. An open language model found vulnerabilities in a real security test at a price that inverts the economics of attack completely, which is laid out in Mythos in the Basement. And the threshold for offensive operations fell some time ago, which I took apart in Mythos Supposedly Cracked the NSA. Anyone who wants to know how far the automation now reaches will find the least comfortable case in The Day the Earth Stands Still, where a model broke out of its test environment and entered the production systems of another company.

The Fine Falls on Whoever Reports Late

Now it gets uncomfortable, and not for the attackers. The act contains several criminal and administrative penalty provisions. Article 31 paragraph 1 covers obtaining information by deception and using disclosed data for purposes other than the declared one, carrying up to 3 years of imprisonment or a monetary penalty of up to 360 daily rates. Article 31 paragraph 2 provides for a fine of up to 200,000 francs against anyone who fails to meet reporting and cooperation duties, or meets them late, incompletely, or incorrectly. A legal entity that reports its beneficial owners too late therefore risks a sum that is existential for many small structures.

A mirror-image penal provision for the case where the register-keeping body breaches its duty of protection and data flows out does not appear in the same act. It obliges the register keeper under Article 12 paragraph 4 to protect the data, it demands logging of every processing operation under Article 12 paragraph 6 and retention of those logs for 10 years, and it regulates appeal routes against official decisions. A sanction covering the case where the data flows out despite these duties does not appear there. I am not claiming that no claims exist at all, since other legal bases govern that question and I am not the person to answer it. I am recording only what this particular act contains and what it does not.

Set the 2 sides next to each other without judging them, because they judge themselves. The citizen delivers under threat of penalty. The state safeguards under a duty of care carrying no penal norm of its own. And when things go wrong, the citizen receives a notification under Article 34 of the General Data Protection Regulation and an email address for questions.

For the management bodies of essential and important entities, German law has recently taken a different direction, and that is the comparison that hurts here. The German federal act on information security dated December 2, 2025, obliges the management bodies of the organizations it covers, under Section 38 paragraph 1, to implement risk management measures and supervise their implementation. Paragraph 2 makes clear that management bodies breaching these duties are liable to their own organization for culpably caused damage under the rules of corporate law. Paragraph 3 adds a duty of regular training. This does not extend to the private economy as a whole, but it does put the leadership of every covered organization personally on the hook. I consider that correct, and that is exactly why the comparison lands the way it does.

Why This Is Not a Liechtenstein Problem

It would be convenient to file the incident as the operating accident of a small country. That convenience does not survive the first follow-up question. Article 10 of the act provides that the register be interconnected through the central European platform with the central registers of other member states of the European Economic Area. Registers therefore talk to one another because policy explicitly wanted that, and every connection between 2 holdings is simultaneously an additional attack surface.

In parallel, Directive (EU) 2023/2226 has applied since January 1, 2026, known in common usage as DAC8, requiring reporting providers to collect identification and transaction data and transmit it to national tax authorities, with subsequent exchange between states and first reports for 2026, which have to be filed by September 30, 2027. Liechtenstein belongs to the European Economic Area and is not a member state of the European Union, which is why DAC8 does not apply there directly. That distinction matters to me, because it went missing in the excitement of the past days.

The piece that carried this story into the German-speaking sphere came from the Blocktrainer editorial team, which frames the incident as fresh ammunition against DAC8. That frame carries further than I initially cared to admit, and it still does not carry all the way. What happened in Vaduz proves nothing about DAC8 itself, since neither crypto-assets nor transaction data sat in that register. It proves something about the shared construction of all these systems, and that is the stronger argument, because a question of jurisdiction cannot wipe it away.

The connection holds all the same, and it is structural in nature. The VwbP links people to legal entities. A reporting system for crypto-assets links people to concrete movements of wealth. Whoever merges both no longer holds a register, they hold a target list. And because a record does not age the way a human being does, it still functions as a target list long after the entries have gone stale. Somebody recorded as wealthy in 2026 may be asked about it in 2031, regardless of what became of the wealth in between. On the question of how much a state may know before it becomes a hazard to its own citizens, I wrote at greater length in When Tehran Writes and Brussels Stays Silent and in The Sleepless Question About the Ship of State.

What Actually Matters Now

For the people concerned, the next danger is not the great intrusion but the friendly message. A record made of surname, given name, date of birth, and nationality permits an approach that feels authentic, because it knows things that supposedly only an authority could know. That is precisely why the quality of fraud attempts rises after every register outflow, and it rises abruptly. Anyone called or written to over the coming months who is confronted with correct personal details should read that correctness as a warning sign rather than as proof.

2 rules are enough to start with and will spare you most of the damage. The first is that knowledge of personal data legitimizes nobody, because that data now sits with far too many people. The second is that every contact gets verified through a channel you choose yourself, meaning the official number of the authority or the bank and never the callback number from the message. Anyone affected in Liechtenstein, or possibly affected, can turn to the central information point set up by the government, which takes questions by email at vwbpfragen@llv.li. How easily a confident-sounding counterpart can talk an access credential out of someone is something I described using the interrogation tactic in We Have Already Extracted 98 Percent of Your iPhone.

There is a further question worth asking for anyone recorded as a beneficial owner anywhere or holding a stake in a foreign structure. It is not whether your own data was part of this particular incident, since the notification under Article 34 of the General Data Protection Regulation will settle that. It is how many mandatory registers you appear in altogether, in which states those registers are kept, and which fields are stored in each. Most people I put this question to name a handful off the top of their head and underestimate the actual number considerably. Anyone who does not know that list cannot even assess, in an emergency, which combination from which sources might be assembled against them.

For everyone operating systems themselves, the lesson is drier and more expensive. Check which of your applications come from a single vendor, and ask that vendor in writing how they will notify you in a serious case. Make sure your logs are actually being reviewed, because a log nobody reads is an archive for later reconstruction rather than a detection capability. And assume that a successful intrusion at your place will run just as quietly as it did in Vaduz, where several days sat between the access and the confirmed finding.

Until Wednesday Afternoon

I wrote an email to all clients today, and it turned out differently from what I had planned. It opens with a Leberkässemmel, the warm meatloaf roll that passes for breakfast where I come from, hitting the floor on Friday morning when the alarm went off, and it closes with the sentence that I am taking a break now. In between sit the figures from the weekend, the systems that held, and the uncomfortable observation that attacking has grown cheaper while more and more people have a model assemble their applications for them without understanding what they are putting into service.

While writing that email I noticed that I never warned about exactly this situation with a polemical smile on my face. That was a misjudgment, and I am correcting it here in public. I have written about the economics of attack, about models, about thresholds, about registers, and every single time I acted as though this were a topic for other people. It has not been one for a long time. Between my own weekend and that night in Vaduz there is no difference in kind, only a difference in outcome.

Until Wednesday afternoon I am out. I have to process this weekend, I urgently need a fresh Leberkässemmel, and after that I sit down and write software that protects servers, websites, databases, and WordPress installations. Not as a product idea, but because I saw 8 open systems in 15 checks and can no longer claim afterward that I did not know.

And what happens in Vaduz in the meantime? The principality will run an investigation, publish a report, and eventually announce an improvement. The 31,000 records stay out there regardless, permanently, because the Court in Luxembourg already wrote precisely that down in 2022. What I want to know more precisely next time is the question nobody asked this week: how many authorities across Europe run their mandatory registers on portals from the same vendor? When I am back on Wednesday, that question is where I start.

Editorial note: This article reflects the state of knowledge as of August 3, 2026. The crisis unit of the Liechtenstein government had announced a further statement for that day, which had not been published by the editorial deadline. What remains open in particular is the number of natural persons affected, the route of the attack, the dwell time inside the system, and the status of the 2 portals taken offline as a precaution. The article will be updated once substantiated new findings are available.

References

  • Court of Justice of the European Union. (2022). *Press release 188/22 on the judgment in joined cases C-37/20 and C-601/20, Luxembourg Business Registers and Sovim*. https://curia.europa.eu/site/upload/docs/application/pdf/2022-11/cp220188en.pdf
  • European Commission, Directorate-General for Taxation and Customs Union. (2026). *DAC8, Directive on Administrative Cooperation (tax transparency for crypto-assets)*. https://taxation-customs.ec.europa.eu/taxation/tax-transparency-cooperation/administrative-co-operation-and-mutual-assistance/directive-administrative-cooperation-dac/dac8_en
  • Federal Republic of Germany. (2013). *Bundesmeldegesetz (BMG), Section 51, information blocks*. https://gesetze.legal/bund/bmg/51
  • Federal Republic of Germany. (2025). *Act implementing the NIS 2 Directive and regulating essential principles of information security management in the federal administration, BGBl. 2025 I Nr. 301, containing the BSI Act of December 2, 2025, Section 38*. https://www.recht.bund.de/bgbl/1/2025/301/regelungstext.pdf?__blob=publicationFile&v=3
  • Government of the Principality of Liechtenstein. (2026, August 2). *Unberechtigter Zugriff von Dritten auf Verzeichnisdaten* [Press release]. https://www.regierung.li/medienportal-medium/16182/234653/medienmitteilung
  • Meier, G. (2026, August 2). *Cyberangriff auf Liechtenstein, Daten von wirtschaftlich Berechtigten gestohlen*. Landesspiegel. https://landesspiegel.li/2026/08/daten-von-31000-wirtschaftlich-berechtigten-gestohlen/
  • Office of Statistics Liechtenstein. (2025). *Bevölkerungsstand per 31. Dezember 2024*. Statistikportal of the Liechtenstein National Administration. https://www.statistikportal.li/de/themen/bevoelkerung/bevoelkerungsstand
  • Schweizer Radio und Fernsehen. (2026, August 2). *Cyberangriff auf Wirtschaftsdaten im Fürstentum Liechtenstein*. SRF News. https://www.srf.ch/news/international/hackerangriff-cyberangriff-auf-wirtschaftsdaten-im-fuerstentum-liechtenstein
  • Principality of Liechtenstein. (2021). *Act of December 3, 2020, on the register of beneficial owners of legal entities (VwbPG), LGBl. 2021 Nr. 33, LR 952.8*. Lilex. https://www.gesetze.li/konso/pdf/2021033000?version=1
  • René. (2026, August 2). *31.000 Rechtsträger betroffen: Datenklau in Liechtenstein liefert neue Munition gegen DAC8*. Blocktrainer. https://www.blocktrainer.de/blog/31000-rechtstraeger-betroffen-datenklau-in-liechtenstein-liefert-neue-munition-gegen-dac8

Disclaimer: This article reflects the author’s own research and opinion as of the publication date shown above; later findings or legal changes may have overtaken it, so always check that date. Sources are cited for independent verification, and no liability is accepted for third-party studies. This is general information, not medical, legal, or professional advice: for medical questions see a doctor, for legal questions a lawyer, and in an acute crisis contact emergency services or a crisis helpline.

Read the full disclaimer

About the header image: it is AI-generated. Cheaper than a photo shoot, and I have made my peace with the age of AI. Everything inside the article is real, the diagrams, the skulls, the findings, and every word. The machine gets the opening shot and not one inch past it.