Liechtenstein disclosed an unauthorized intrusion into its VwbP register, the national database of beneficial owners used for anti-money laundering and counter-terrorism financing compliance, after attackers exfiltrated copied data tied to about 31,000 legal entities and their beneficial owners. Government statements said the intrusion occurred during the night of July 30 and that the stolen records may affect a substantial share of the country’s residents, given Liechtenstein’s population of roughly 41,000. Authorities said there was no evidence that data in the register had been modified or deleted.
The government temporarily disabled external access to the register through llv.li, classified the incident as a personal data breach under GDPR Article 33, and said affected individuals would be notified under GDPR Article 34. A crisis team led by Prime Minister Brigitte Haas, with Justice Minister Emanuel Schädler involved, was convened to manage the response. Public reporting described the stolen information as covering all economically beneficial owners recorded in the system, while the responsible threat actor, intrusion method, and specific compromised infrastructure have not been identified.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
On August 2, 2026, Liechtenstein formally confirmed the crisis cell led by Prime Minister Brigitte Haas and Justice Minister Emanuel Schädler. Authorities also made the VwbP register temporarily inaccessible to external users via llv.li and said affected persons would be notified under GDPR procedures.
On August 2, 2026, the Government of Liechtenstein publicly announced that an unauthorized intrusion had affected the VwbP system. It said copied data relating to about 31,000 legal entities and their beneficial owners had been exfiltrated, with no evidence at that stage of data modification or deletion.
On the afternoon of August 1, 2026, authorities transmitted initial confirmed findings about the VwbP breach to the government. The same evening, a crisis cell was formed to coordinate the response.
The government was informed on July 31, 2026 that the incident may have been a successful cyberattack. This marked the escalation from technical irregularities to a suspected confirmed compromise.
On July 30, 2026, the Office of Justice detected irregularities in the VwbP system and contacted the Office of Information Technology. Authorities immediately implemented protective measures and disconnected the register from the network.
An unknown actor illegally accessed Liechtenstein's VwbP beneficial-owners register during the night of July 30, 2026. The intrusion ultimately led to the exfiltration of copied data tied to about 31,000 legal entities and their beneficial owners.
Unknown attackers accessed Liechtenstein's Register of Beneficial Owners for a two-day period beginning on July 29, 2026. The later investigation found data tied to about 31,000 entities was exfiltrated during the intrusion.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcetherecord.media
Open sourcesecurityweek.com
Open sourcevaterland.li
Open sourcemalware.news
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.