Richmond Park Associates - FZCO is a United Arab Emirates Free Zone Company with limited liability, incorporated pursuant to Law n. 16 of 2021, and registered with the Dubai Silicon Oasis Free Zone.

During the night of 29-30 July 2026, attackers breached one of Liechtenstein’s most sensitive government databases, the Register of Beneficial Owners (Verzeichnis wirtschaftlich berechtigter Personen – VwbP). By the time the intrusion was detected and the system secured, data relating to approximately 31,000 legal entities had reportedly been exfiltrated.
On 2 August, the Government of Liechtenstein confirmed that “an unknown perpetrator gained unauthorised digital access” to the register. The VwbP forms a central component of the country’s anti-money laundering and counter-terrorist financing framework, recording the natural persons who ultimately own or control companies, foundations and trusts established in Liechtenstein. The register was introduced as part of the jurisdiction’s wider regulatory reforms following the abolition of banking secrecy in 2017.
Detection and response
According to the authorities, irregular activity was first identified on 30 July by the Office of Justice. The Office of Information Technology immediately isolated the affected system and took it offline as a precaution. The Government was informed the following day, and preliminary forensic analysis confirmed that data relating to approximately 31,000 legal entities had been copied from the system.
On the evening of 1 August, Prime Minister Brigitte Haas and Justice Minister Emanuel Schädler convened a crisis task force to coordinate the investigation, oversee notifications to affected parties and supervise remediation efforts. Speaking to Swiss broadcaster SRF’s Tagesschau, Prime Minister Haas stated that, as of the Government’s public announcement, no ransom demand had been received, and the compromised data had not appeared on known dark web marketplaces.
Whilst those facts may suggest that the attack was not immediately financially motivated, they do not exclude other possibilities, including targeted intelligence gathering, extortion at a later stage, or the gradual exploitation of the stolen information.
Nature of the compromised data
The VwbP contains personally identifiable information relating to beneficial owners, including names, dates of birth, nationality and country of residence. These records identify the individuals who ultimately own or control Liechtenstein companies, foundations and trust structures, information collected pursuant to international AML standards and broadly aligned with the objectives of the EU’s Fifth Anti-Money Laundering Directive.
At present, the Government has stated that there is no evidence that the data was altered or destroyed. The available information indicates that the attackers copied data from the register rather than attempting to manipulate or disrupt its contents.
Nevertheless, the theft of beneficial ownership data presents significant risks. Unlike ordinary personal information, these records identify individuals associated with substantial private assets and complex corporate structures. Such information could facilitate highly targeted phishing campaigns, business email compromise, identity fraud or other social engineering attacks by enabling attackers to impersonate trusted advisers or exploit knowledge of legitimate corporate relationships. The register, established in 2021 to enhance corporate transparency, has consequently become a repository of exceptionally valuable intelligence for malicious actors.
GDPR implications
The Government is treating the incident as a personal data breach under the General Data Protection Regulation (GDPR), triggering notification obligations under Articles 33 and 34. Although Liechtenstein is not a member of the European Union, it participates in the European Economic Area and applies the GDPR through the EEA framework.
The authorities have established a dedicated contact address (vwbpfragen@llv.li) for affected individuals and their advisers, while external access to the register has been suspended pending completion of the investigation.
To date, no threat actor has claimed responsibility for the attack, and the Government has not disclosed either the technical means by which the intrusion occurred or any attribution to a particular group. The absence of public attribution leaves open a range of possible motives, including financially motivated cybercrime, corporate espionage or state-sponsored intelligence collection.
Implications for beneficial ownership registers
The incident highlights a broader challenge facing jurisdictions that have implemented centralised beneficial ownership registers. Across the European Economic Area, such registers have been established to increase corporate transparency and deter the misuse of legal entities for money laundering, sanctions evasion and other financial crime.
However, concentrating highly sensitive ownership information within a single searchable database inevitably creates an attractive target for sophisticated cyber attackers.
For Liechtenstein, the breach certainly carries broader reputational implications. Since the end of banking secrecy in 2017, the principality has sought to position itself as a transparent international financial centre. The beneficial ownership register has been an important element of that strategy. A compromise of the register therefore raises questions not only about cybersecurity controls but also about the resilience of the digital infrastructure supporting modern financial transparency initiatives.
Next steps
The Government has indicated that further updates will be provided as the forensic investigation progresses and affected individuals continue to be identified and notified. Trustees, fiduciaries and professional advisers connected with Liechtenstein structures have been encouraged to assess whether their clients may have been affected and to remain vigilant for phishing attempts or other fraudulent activity exploiting the compromised information.


