CSIDB logo
Incident

Liechtenstein Register of Economic Beneficiaries

Incident posture

Attack window
Jul 2026
Location
Liechtenstein
Status
Unknown
CIA posture
Available to members
Updated
2026-08-08 20:48

Linked entities

Victim
Liechtenstein Register of Economic Beneficiaries
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Jul 2026
Discovered
Jul 2026
Disclosed
Aug 2026
Resolved
Pending

Summary

A cyberattack gained unauthorized access to Liechtenstein's register of economic beneficiaries, exposing the personal data of approximately 31,000 individuals linked to companies, foundations and trusteeships. The breach was detected after the intrusion, prompting officials to shut the system offline, secure the data, and establish a crisis unit to investigate, with no indication that any information was altered or deleted.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

A cyberattack targeted Liechtenstein's register of economic beneficiaries, compromising the personal data of approximately 31,000 individuals. The unauthorized access occurred during the night from Wednesday into Thursday of the previous week, according to government statements. Authorities became aware of the breach on Thursday and promptly initiated measures to secure the affected data. As part of the response, the system hosting the register was taken offline to prevent further exposure. Officials confirmed that there was no evidence indicating that any of the accessed data had been altered or deleted.

The register of economic beneficiaries maintains information about the individuals behind companies, foundations and trusteeships, supporting national efforts to combat money laundering and terrorist financing. Liechtenstein, with a population of roughly 40,000, lies between Switzerland and Austria and relies heavily on its financial sector for economic activity. Following the incident, the government convened a crisis unit over the weekend to lead the investigation into the attack. The unit's mandate includes determining the scope of the breach and identifying any potential vulnerabilities. No further details about the attackers or their motives were disclosed in the available source.

Sources

Sources available to members: 2 sources.

CSIDB