Liechtenstein's beneficial ownership register breached, 31,000 entities exposed
Hackers exfiltrated data on around 31,000 companies, foundations and trusts from Liechtenstein's Register of Beneficial Owners, reopening the privacy debate for wealthy families.
Liechtenstein has confirmed that its Register of Beneficial Owners was breached, with copies of data on around 31,000 legal entities taken by unknown attackers. The government disclosed the incident on 3 August 2026 and closed the register to external users while it assessed the damage.
Attackers gained access to the register, known locally as the VwbP, during the night of 29 to 30 July, according to the government statement. Officials at the Office of Justice noticed irregularities on 30 July, and the Office of Information Technology then took the affected system offline. A crisis unit led by Prime Minister Brigitte Haas and Justice Minister Emanuel Schädler was convened over the following weekend, with the first confirmed findings reaching the government on 1 August.
What was taken
The register holds information on the beneficial owners of companies, foundations and trusts, the structures for which Liechtenstein is best known among wealthy international families. Reporting on the stolen data points to names, dates of birth, nationality and country of residence for the individuals behind those entities. The government said there was no evidence that records had been altered or deleted, and, at the time of writing, no group had claimed responsibility or made a ransom demand.
Vaduz confirmed that the breach amounts to a personal data breach under the General Data Protection Regulation. The VwbP was established under a 2021 act that implemented the European Union’s fifth Anti-Money Laundering Directive, and it exists to help prevent money laundering and terrorist financing.
A sharper privacy debate
For family offices, the incident lands on a sensitive point. Beneficial ownership registers were built to make ownership more visible to regulators and, in several jurisdictions, to the public. Wealthy families and their advisers have long argued that naming individuals in a central database carries real security and privacy risks, from kidnap and extortion to more mundane reputational exposure. In 2022 the Court of Justice of the European Union restricted general public access to such registers on privacy grounds, and a breach of this kind gives that argument fresh weight.
The worry goes beyond leaked data. The register itself is becoming part of the financial plumbing. Steve Lamb, chief executive of company-registry firm Kyckr, told WealthBriefing that registries are turning into critical financial infrastructure that thousands of institutions rely on as an authentic source, and that they should be resourced accordingly. When the source can be compromised, he argued, confidence in the whole chain suffers.
What families should watch
Anyone with a Liechtenstein company, foundation or trust may want to establish, through their advisers, whether their entity sits among the 31,000 affected, and to review the physical and digital security that follows from a name and address becoming public. Advisers will also be watching how Vaduz handles its GDPR notification obligations and whether the stolen data surfaces elsewhere.
Liechtenstein remains a core jurisdiction for private wealth structuring, and one attack does not change that. It does, however, illustrate a wider point: the same transparency rules that made ownership legible to regulators have created concentrated stores of sensitive data, and those stores are now a target. The investigation continues.