---
title: "Liechtenstein beneficial-ownership register cyberattack"
description: "Liechtenstein beneficial-ownership register cyberattack: verified timeline, impact and response through October 7, 2026."
incident_type: "Cybersecurity incident"
status: "active"
last_modified: "2026-10-07"
canonical_url: "https://www.ally.security/incidents/liechtenstein-beneficial-ownership-register-cyberattack-2026"
markdown_url: "https://www.ally.security/incidents/liechtenstein-beneficial-ownership-register-cyberattack-2026.md"
stix_url: "https://www.ally.security/incidents/liechtenstein-beneficial-ownership-register-cyberattack-2026/stix.json"
---

# Liechtenstein beneficial-ownership register cyberattack

Liechtenstein’s government reported a cyberattack that interrupted external access to its beneficial-ownership register.

Last modified Oct 7, 2026 · 1 source

## Summary

- **Environment:** Register of Beneficial Owners of Legal Entities (VwbP)
- **Operational impact:** External register access suspended
- **Financial impact:** No incident cost established in the reviewed evidence

## What happened

[Liechtenstein’s government](https://www.regierung.li/) reported a cyberattack that interrupted external access to its beneficial-ownership register. [1](#source-1)

## Impact

The government acknowledged stolen data but reported no indication of publication. [1](#source-1)

Backup comparisons found no modification of register data. [1](#source-1)

## Timeline

### July 30, 2026 — Cyberattack

Register access disrupted. [1](#source-1)

### October 2, 2026 — Recovery announcement

Government published its [recovery update](https://medienportal.regierung.li/medienportal-medium/16444/234948/0/medienmitteilung). [1](#source-1)

### October 7, 2026 — Briefing updated

This briefing was last reviewed and updated on October 7, 2026.

## Threat Group & Attack Vector

The reviewed disclosure does not establish the initial access method.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

The government announced limited access would resume October 5 after remediation, requiring in-person identification. [1](#source-1)

It was procuring an independent review. [1](#source-1)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/liechtenstein-beneficial-ownership-register-cyberattack-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Following the cyberattack: limited resumption of VwbP operation

official · Government of the Principality of Liechtenstein · Oct 2, 2026

<https://medienportal.regierung.li/medienportal-medium/16444/234948/0/medienmitteilung>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   Liechtenstein beneficial-ownership register cyberattack: The government announced limited access would resume October 5 after remediation, requiring in-person identification.
2. **Resulted In · 100% confidence · current**  
   Liechtenstein beneficial-ownership register cyberattack: Liechtenstein’s government reported a cyberattack that interrupted external access to its beneficial-ownership register.
3. **Resulted In · 100% confidence · current**  
   Liechtenstein beneficial-ownership register cyberattack: The government acknowledged stolen data but reported no indication of publication.
4. **Disclosed At · 100% confidence · current**  
   Liechtenstein beneficial-ownership register cyberattack: 2026-10-02
5. **Resulted In · 100% confidence · current**  
   Liechtenstein beneficial-ownership register cyberattack: Backup comparisons found no modification of register data.
6. **Resulted In · 100% confidence · current**  
   Liechtenstein beneficial-ownership register cyberattack: It was procuring an independent review.
7. **Affected Organization · 100% confidence · current**  
   Liechtenstein beneficial-ownership register cyberattack: Government of the Principality of Liechtenstein
8. **Occurred At · 100% confidence · current**  
   Liechtenstein beneficial-ownership register cyberattack: 2026-07-30

</details>
