A bombshell in low-key Liechtenstein: hackers have got hold of all the data from the register of beneficial owners. Photo: Shutterstock

A bombshell in low-key Liechtenstein: hackers have got hold of all the data from the register of beneficial owners. Photo: Shutterstock

Liechtenstein has not lost any money. Its banks have not been hacked. Hackers managed to copy data from the national register of beneficial owners, comprising around 31,000 records relating to companies, foundations and trusts. For a financial centre that has built its reputation on legal certainty and confidentiality, the incident goes far beyond the technical sphere.

The attack took place during the night of 29 to 30 July. According to the government in Vaduz, an as yet unidentified party gained unauthorised access to the Register of Beneficial Owners, which was established in 2021 to implement European anti-money laundering directives. The authorities detected irregularities as early as Thursday, took the system offline as a precaution and, by the weekend, had set up a crisis unit led by Prime Minister Brigitte Haas and Justice Minister Emanuel Schädler.

At this stage, the authorities say they have found no evidence that any data has been altered or deleted. No group has claimed responsibility for the attack, no ransom demand has been made, and the stolen information has not been found on the dark web. However, the absence of blackmail does not diminish the significance of the incident.

The register in question does not contain clients’ bank accounts or the systems of financial institutions. It lists the beneficial owners of legal entities – the individuals who actually control companies, foundations or trusts – in order to meet international transparency requirements relating to the fight against money laundering and the financing of terrorism.

The paradox is striking. Beneficial ownership registers have been set up across Europe to enhance transparency. They are now themselves becoming prime targets for cybercriminals. With a single breach, an attacker can gain an extremely detailed picture of legal structures, control relationships and assets organised across thousands of entities.

A question of reputation rather than technical ability

For Liechtenstein, the main issue is one of reputation. Since the end of banking secrecy and the tightening of international rules, the principality has repositioned itself as a financial centre that complies with transparency standards, whilst highlighting the quality of its legal framework. Any compromise of the register responsible for demonstrating this compliance directly undermines this selling point.

Simon Tribelhorn, director of the Liechtenstein Bankers’ Association, sums up the situation cautiously: the incident is “regrettable” and “should not be taken lightly”, whilst emphasising that no bank and no customers’ banking data have been compromised.

The issue extends far beyond Liechtenstein’s 40,000 inhabitants. Luxembourg, too, has a register of beneficial owners, established in line with the same European obligations. Both financial centres are home to a very large number of companies, funds and international wealth management structures. They therefore share the same vulnerability: registers intended to enhance transparency are becoming critical infrastructure.

The attack also serves as a reminder that a financial centre no longer protects just financial assets, but also the databases that describe the structure of those assets. For an attacker, knowing who controls which companies, foundations or vehicles can be almost as valuable as access to a bank account.

In Liechtenstein, the priority is now to identify those responsible for the attack and to inform the organisations concerned. But the shockwaves are already being felt beyond the principality’s borders. For all jurisdictions specialising in financial services, the message is clear: trust no longer depends solely on compliance rules, but also on the ability to protect the digital infrastructure that makes them possible.