GoFirm
Back to Blog
Case Studies·3 min read

The specially created account that opened Liechtenstein's beneficial owners register

By GoFirm

On 30 July 2026, Liechtenstein's Office of Justice discovered that attackers had spent the previous night inside the Register of Beneficial Owners (VwbP), the country's central database identifying the real individuals behind the companies, foundations and trusts registered in the principality. The register exists for one purpose: to stop anonymous shell structures from laundering money through one of Europe's oldest private banking centres. The government in Vaduz confirmed the intrusion publicly on 3 August, four days after it happened.

Officials have called it a targeted, technically advanced attack, but the one mechanism they have actually named is simpler than that description suggests. A user account that should not have existed was created inside the system, and nothing stopped it from working. Through that account, the attackers reached in and copied data tied to approximately 31,000 legal entities, including the names, dates of birth, nationalities and countries of residence of the individuals who ultimately own or control them. The government has said there is no evidence any record was altered or deleted, only that copies were taken.

The Office of Justice detected the intrusion within hours, assembled a crisis unit over the following weekend, and pulled the register offline for external users while the investigation continues. That response was faster than most breaches in this series manage. It did not change what had already left the building. An independent evaluation by MONEYVAL, the Council of Europe's anti-money-laundering assessment body, had flagged gaps in how the register's data was monitored as recently as October 2025, months before an account nobody has yet explained was used to copy the file.

The register exists precisely because financial secrecy has costs, and Liechtenstein built it to satisfy international anti-money-laundering standards that depend on knowing who truly owns a company, not just whose name sits on its paperwork. That same design makes the data itself valuable to take. A single export now tells whoever holds it exactly which real individuals control tens of thousands of Liechtenstein entities, information that intelligence services, criminal groups and blackmailers would each put to different use, but use nonetheless. Liechtenstein has not disclosed a ransom demand, a buyer, or a leak site listing. What it has disclosed is that a database built to expose hidden ownership became, for one night, itself hidden from the people responsible for guarding it.

The defences that failed here were not weak by conventional standards. This was not an unpatched appliance or a reused password. Officials themselves describe the intrusion as targeted and technically advanced, the kind of attack conventional perimeter security is built to catch. It did not need to defeat that perimeter. It needed one thing: a new account, provisioned with access to a database holding some of Europe's most sensitive ownership records, that nobody with the authority to say no was ever asked to approve.

Provisioning an account with access to the Register of Beneficial Owners is an execution event. Before that account can be created or granted query and export rights, GoFirm sends a real-time confirmation request to the named system owner inside the Office of Justice, on their own registered device, over a channel the request itself never touches. No confirmation, no account. No account, no access to copy anything.

The same control applies to the export itself. Before 31,000 records can leave the register in a single action, the named data protection authority confirms it on a device the attacker was never near. A specially created account, however technically sophisticated the attack behind it, cannot produce that confirmation on its own. The execution boundary holds regardless of how the access was obtained.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai,
the collective intelligence and governance Network for Security, Resilience & Defence teams.

Deploy AI securely. Provide assurance continuously.

References


1. Euronews. 2026. Cyberattack hits Liechtenstein's anti-money laundering data register, Vaduz says. Euronews, 3 August 2026.
2. Security Affairs. 2026. 31,000 records compromised in breach of Liechtenstein companies and foundations register. Security Affairs, 3 August 2026.
3. AML Intelligence. 2026. Hackers breach Liechtenstein beneficial ownership register, access data on 31,000 entities. AML Intelligence, 3 August 2026.
4. TechNadu. 2026. Hackers exfiltrated data on 31,000 entities from Liechtenstein register. TechNadu, 4 August 2026.

Share this article