Liechtenstein Ownership Register Breach Exposes 31,000 Entities

Hackers gained unauthorised access to Liechtenstein’s beneficial ownership register and copied information relating to approximately 31,000 companies, foundations and trusts.
Unknown perpetrators accessed the system during the night of 29–30 July before authorities detected irregularities and took it offline, the principality’s government said, Public reporting indicates that .
Transparency data is also sensitive data
Ownership registers are essential to anti-money laundering investigations, but they also hold information that may be valuable to criminals, hostile intelligence services and extortionists. Operators must balance legitimate access with strong authentication, monitoring and data minimisation.
Financial institutions should treat register outages or compromised data as a source-quality issue. Customer due diligence may need to rely temporarily on corporate documents and independent verification rather than assuming copied or altered records remain authoritative.
The incident highlights the need for resilient public financial infrastructure. Registers should maintain tamper-evident logs, tested recovery procedures and clear notification processes for entities whose information may have been exposed.
Immediate response priorities
Authorities need to determine what fields were copied, whether records were altered and which users or systems were involved. A breach affecting ownership data may expose addresses, control relationships and information about trusts or foundations even when no financial account was compromised.
Entities recorded in the register should be alert to targeted phishing and impersonation using accurate corporate details. Financial institutions should verify unusual instructions independently and avoid treating knowledge of private ownership information as proof that a caller is legitimate. Restoration should include credential resets, log review and validation that published records match authoritative filings.
Controls for public registers
- Strong authentication for privileged and bulk-access users.
- Real-time detection of unusual searches or large downloads.
- Immutable logs showing access and changes to records.
- Recovery procedures that validate data before the service reopens.
Next focus: The investigation should clarify whether the attackers only copied records or also obtained the ability to alter them. That distinction affects both notification and the level of independent data validation required.



