Criminal Attack on the VwbP: Potential Vulnerability Identified
The forensic investigation into the cyberattack on the directory of beneficial owners has identified a potential point of entry. A more detailed analysis is currently underway. The investigation into the circumstances of the incident is continuing, and law enforcement agencies are conducting their probe. Over the past 48 hours, the crisis management team has implemented various measures and initiated additional ones.
Preliminary Findings on the Course of Events
The “Register of Beneficial Owners,” or VwbP for short, was the target of a cyberattack in the middle of last week. Forensic investigations and related analyses into the course of the attack and how the security measures were bypassed are ongoing. An initial indication of a possible point of entry for the attack has been identified. It was a targeted, technically sophisticated attack on a highly complex security infrastructure.
The preliminary findings also indicate that the VwbP was targeted in a specific and isolated attack. Based on current information, no unauthorized access attempts have been detected on either the state administration’s servers or any other state administration systems.
Nevertheless, the government has ordered that, as a precautionary measure, additional systems containing sensitive data be temporarily taken offline. They will undergo further comprehensive security checks.
Head of Government Brigitte Haas emphasizes: “We are continuing to work around the clock to investigate and implement measures in response to the criminal cyberattack. I would like to reiterate that the VwbP is a tool for transparency and the prevention of criminal offenses. We created the registry in coordination with our European partners and to implement the 5th EU Anti-Money Laundering Directive. The attack on us is also an attack on international compliance standards.”
The financial center strategy, which was developed and is jointly supported by the authorities and financial market participants, states this very clearly. Key measures include the timely implementation of all relevant EU regulations and our full integration into the European system of financial supervision; as well as the automatic exchange of information in tax matters, the implementation of OECD initiatives to combat profit erosion and profit shifting, and the proactive fight against money laundering and terrorist financing. Liechtenstein’s full compliance with all international standards and its pioneering role in combating financial crime are also regularly confirmed by international organizations such as MONEYVAL, the International Monetary Fund, and the rating agency S&P Global.
Data subjects are informed
An important measure is the notification of the affected individuals regarding this attack and their data, as required by data protection law. The Data Protection Act stipulates that detailed information must be provided. To the extent that the authorities have the data on file, the individuals will be notified immediately. However, since not all contact information is stored in the directory—for example, residential addresses are missing—individual notifications are being delayed. It was therefore agreed with the associations that the agency will provide the information to the legal entities, which will then inform the affected beneficial owners, in order to achieve a solution that is acceptable under data protection law. Thus, no additional data beyond what is required by the Anti-Money Laundering Directive will be disclosed to government agencies.
In addition, an information center has been set up as an additional channel for questions and information for those affected. It will be available starting Tuesday, August 4, 2026, at 4:00 p.m. by phone at +423 232 90 00 or by email at vwbpfragen@llv.li. The information center can be reached by phone on weekdays from 8:00 a.m. to 12:00 p.m.
No customer or asset data was affected
Liechtenstein has repeatedly committed itself to maintaining high standards in compliance with relevant international and European requirements in the fight against money laundering and terrorist financing, and consistently implements these standards. Compliance with international and European standards has been a key pillar of the financial center strategy for years.
For this reason, among others, the VwbP was introduced in 2021 as part of the implementation of the 5th Anti-Money Laundering Directive. This data is used by authorized agencies to combat money laundering, predicate offenses to money laundering, and terrorist financing. The registry lists the name of the legal entity as well as the last name, first name, date of birth, nationality, and country of residence of the beneficial owners.
No addresses or phone numbers are collected. Likewise, no financial data regarding the legal entities—such as revenue, assets, or dividends—is collected. Accordingly, no conclusions regarding assets or other financial data can be drawn from the data obtained.
Law enforcement agencies deployed
Over the weekend, the Office of Justice filed a criminal complaint against persons unknown. Law enforcement authorities immediately launched an investigation. Digital evidence is being analyzed and pursued in cooperation with European authorities.
The List of Beneficial Owners
The VwbP is maintained for the purpose of preventing money laundering and terrorist financing and complies with the requirements of the 5th EU Anti-Money Laundering Directive. It contains public and non-public data on the beneficial owners of companies, foundations, and trusts in Liechtenstein. The Act on the Register of Beneficial Owners of Legal Entities (VwbPG) entered into force in 2021.