ctipilot.ch

Liechtenstein VwbP beneficial-ownership register breach (July 2026)

incident · incident:liechtenstein-vwbp-register-breach-2026-07

Unauthorised digital access overnight into 2026-07-30 to Liechtenstein's Verzeichnis wirtschaftlich berechtigter Personen (VwbP), the national beneficial-ownership register operated by the Amt fuer Justiz under the VwbPG implementing the EU 5th Anti-Money-Laundering Directive; copies of records for roughly 31,000 legal entities were taken. The government declared it a personal-data breach under GDPR Article 33, convened a crisis unit under Head of Government Brigitte Haas and Justice Minister Emanuel Schaedler, and progressively took the eMWST VAT portal, the Lides reporting platform, the central account register and the Intax tax system offline as precautions. First forensic findings describe a targeted attack on the register with no attacks detected on other systems; no initial-access vector, actor or ransom demand had been disclosed (Regierung des Fuerstentums Liechtenstein, 2026-08-02 / 2026-08-03).

Aliases: Cyberangriff auf das Verzeichnis wirtschaftlich berechtigter Personen, Liechtenstein beneficial ownership register hack

Coverage timeline
3
first 2026-08-04 → last 2026-08-09
Peak priority
high
2 high · 1 notable
Sources cited
13
10 hosts
Sections touched
3
active-threats, updates, weekly-top-stories
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
7
pinned v19.2 · see below
2026-08-043 appearances2026-08-09

Hunting pivots

Affected products
Microsoft SharePoint ServerOracle WebLogic Server

ATT&CK techniques

7 techniques observed across 3 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

Collection TA0009

T1213Data from Information Repositories×3

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · 2026-08-05/liechtenstein-vwbp-entry-point-identified-field-set · 2026-08-04/liechtenstein-vwbp-beneficial-ownership-register-breach · ATT&CK page ↗

Command and Control TA0011

T1572Protocol Tunneling×1

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

Evidence: 2026-08-09/weekly-w32-european-government-own-infrastructure-breached · ATT&CK page ↗

Story timeline

  1. 2026-08-09European government's own operating infrastructure was the target this week — a federal document platform, a national beneficial-ownership register, a state treasury and a heat plant, with two of the entry points on no internet-facing asset inventory
    weekly-top-storiesEuropean public bodies in five jurisdictions compromised in one week, and two of the entry points were on no asset inventory
  2. 2026-08-05Liechtenstein VwbP breach: forensics identify a possible entry point, confirm the register was hit in isolation, and publish the exact field set — identity data, no contact details, no financial data
    updatesThe stolen register yields an identity-verification kit, not a contact list — which changes who is at risk
  3. 2026-08-04Liechtenstein's beneficial-ownership register breached: copies of ~31,000 legal entities' records taken, and four more e-government systems pulled offline as a precaution
    active-threatsA targeted attack on Liechtenstein's beneficial-ownership register yielded a targeting dataset on the owners behind Swiss- and EU-administered structures

Where this entity is cited

  • active-threats1
  • updates1
  • weekly-top-stories1

Source distribution

  • presseportal.ch3 (23%)
  • cert.pl2 (15%)
  • admin.ch1 (8%)
  • gr.ch1 (8%)
  • landesspiegel.li1 (8%)
  • persoenlich.com1 (8%)
  • srf.ch1 (8%)
  • telex.hu1 (8%)
  • other2 (15%)

explore in graph

All cited sources (13)

Entries about Liechtenstein VwbP beneficial-ownership register breach (July 2026) (3)

2026-08-09 · view entry permalink →

HIGHexploitedNATOA1

European government's own operating infrastructure was the target this week — a federal document platform, a national beneficial-ownership register, a state treasury and a heat plant, with two of the entry points on no internet-facing asset inventory

If you did nothing this week: peer institutions in five European jurisdictions disclosed compromises of the machinery they run the state with — and in two of them the way in was connectivity and legacy infrastructure that appears on no internet-facing asset inventory.

Switzerland took two of them in 48 hours, at both levels of government. The Bundesamt für Informatik und Telekommunikation, which operates the Confederation's own data centres, disclosed on 4 August that its on-premises SharePoint Servers were compromised and that "rund 200 Konten kompromittiert wurden" — user accounts and technical service accounts alike (Der Bundesrat / BIT, 2026-08-04). The detail that matters for anyone still running on-premises SharePoint is the timing: BIT had begun installing the July updates immediately on release, and staff spotted the anomalies on 28 July while that work was in progress, so the servers are being rebuilt from scratch rather than patched in place. One day later the Canton of Graubünden's IT office reported a compromise of a SharePoint server hosting the cantonal administration's public web presence, reporting on first analysis no accounts compromised and no data exfiltrated (Kanton Graubünden, 2026-08-05); Keystone-SDA reporting adds that two files were placed on the server and their code was not executed (persoenlich.com, 2026-08-05). Neither Swiss disclosure names a CVE, which is why an estate-wide compromise assessment keyed on the July SharePoint exploitation window — not a CVE-scoped patch check — is the operation this pair calls for.

Two further disclosures show the objective shifting from the citizen's data to the state's own authoritative record. Liechtenstein's Amt für Justiz lost copies of the beneficial-ownership register: "Datenkopien von rund 31'000 Rechtsträgern widerrechtlich abgegriffen" (Regierung des Fürstentums Liechtenstein, 2026-08-02), and the government's follow-up media conference published the exact field set — legal-entity name plus surname, first name, date of birth, nationality and country of residence, with no address, telephone number or financial data recorded (Regierung des Fürstentums Liechtenstein, 2026-08-04). That composition is the point: what was taken is an identity-verification kit tied to the natural persons behind Swiss- and EU-administered structures, not a marketing list. In Hungary, Telex.hu reports that the Magyar Államkincstár's Agricultural and Rural Development Office was breached in late July by ByteToBreach — the actor already tracked here for the attack on Romania's national land registry — with experts consulted on attacker-leaked screenshots assessing entry through an Oracle WebLogic server whose fixes date to an October 2017 patch cycle, escalating to Windows domain-administrator rights (Telex.hu, 2026-08-03).

The week's most consequential access path was published on its last day. CERT Polska's follow-up forensic report on the 29 December 2025 attacks on Poland's energy sector discloses a second, previously unnamed victim — a combined heat and power plant supplying about 50,000 residents, where three Siemens PLCs were switched to STOP mode and password-locked, shutting down a steam turbine and the process-water treatment system. The attacker reached it from an already-compromised wind-farm substation by tunnelling over SSH through a cellular router into the distribution system operator's private APN, a mobile network shared by both sites, and then into a WAGO PFC200 controller whose WAN-side web interface answered on factory credentials (CERT Polska incident follow-up report, 2026-08-08). CERT Polska states that "the use of a private APN to gain access to the OT network was the first instance of this attack vector being observed in a real-world cyberattack," and — the sentence European operators should act on — that surveys of organisations using similar solutions "indicated that this configuration was commonly encountered in Poland" (CERT Polska, 2026-08-08). Belgium supplies the fifth shape: Digitaal Vlaanderen confirmed to WIRED that Belgium's Centre for Cybersecurity notified it on 3 March 2026 of a North Korean compromise, that the affected workstation was isolated and exposed credentials rotated, and that the incident is contained — one organisation inside a victim set the researcher built from nearly two years of access to the actors' own servers (WIRED, 2026-08-05).

Triage: a compromised administrative estate of this kind produces telemetry that reads as ordinary operations, so the discriminators are relational rather than atomic. For the SharePoint cases, look for web-application process trees spawning script interpreters and for service-account authentication from hosts those accounts never normally touch — a service account is defined by its narrow, repetitive access pattern, and the deviation is the signal. For the OT path, the discriminator is direction and origin: an inbound management session to a field controller arriving from a peer device inside the carrier APN rather than from the operator's own engineering workstation subnet, and a controller-mode change (run to STOP) with no corresponding change-management window. Legitimate remote maintenance produces the same protocol events; it does not normally originate from another site's equipment.

Im Rahmen der Analyse des Vorfalls wurde festgestellt, dass rund 200 Konten kompromittiert wurden.

Der Bundesrat / Bundesamt für Informatik und Telekommunikation (BIT) 2026-08-04

Dabei wurden Datenkopien von rund 31'000 Rechtsträgern widerrechtlich abgegriffen.

Regierung des Fürstentums Liechtenstein 2026-08-02

To the best of our knowledge, the use of a private APN to gain access to the OT network was the first instance of this attack vector being observed in a real-world cyberattack.

Surveys conducted among organizations using similar solutions indicated that this configuration was commonly encountered in Poland.

CERT Polska (NASK) 2026-08-08

Builds on: 2026-08-05/bit-foitt-swiss-federal-sharepoint-breach-200-accounts · 2026-08-06/canton-graubuenden-sharepoint-server-breach · 2026-08-04/liechtenstein-vwbp-beneficial-ownership-register-breach · 2026-08-05/liechtenstein-vwbp-entry-point-identified-field-set · 2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic · 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · 2026-08-08/dprk-contagious-interview-blast-radius-flemish-government

synthesis09 Aug 23:45Zmulti-sourceOpen finding ↗

2026-08-05 · view entry permalink →

NOTABLEupdateNATOA2

Liechtenstein VwbP breach: forensics identify a possible entry point, confirm the register was hit in isolation, and publish the exact field set — identity data, no contact details, no financial data

UPDATE · originally covered Liechtenstein's beneficial-ownership register breached: copies of ~31,000 legal entities' records taken, and four more e-government systems pulled offline as a precaution (2026-08-04)

The Government of Liechtenstein held a media conference on 2026-08-04 and closed the largest gap in its earlier disclosure. The original coverage recorded that no initial-access vector had been disclosed; the government now states that a first indication of a possible entry point has been identified, with detailed evaluation still running (Regierung des Fürstentums Liechtenstein, 2026-08-04). It characterises the event as a targeted attack at a high technical level against a highly complex security structure, and the isolation finding is now stated positively rather than as an absence: according to current knowledge, no unlawful access attempts were registered against the state administration's servers or its other systems (Regierung des Fürstentums Liechtenstein, 2026-08-04). Further systems holding sensitive data were nonetheless taken off the network as a precaution and put through security checks.

The second addition changes the risk model rather than merely adding detail. The government published exactly what the register holds: the name of the legal entity, plus surname, first name, date of birth, nationality and country of residence of the beneficial owners, with no address or telephone number recorded (Regierung des Fürstentums Liechtenstein, 2026-08-04). Landesspiegel adds that banking systems, client funds, assets, transaction data and bank client data are not affected (Landesspiegel, 2026-08-04). The earlier entry warned of pretexted contact citing verifiable register facts; that assessment now sharpens in a specific direction. What the attacker holds is an identity-verification kit — the legal entity, the full name, the date of birth, the nationality, the country of residence — and not a way to reach anyone. That combination fits identity impersonation and account-recovery abuse aimed at the fiduciaries, trustees and banks who administer these structures considerably better than it fits mass phishing of the beneficial owners, because the attacker must source contact details elsewhere before they can use any of it.

The notification mechanics are themselves worth publishing as a defensive signal. Because the register holds no contact data, the Amt für Justiz cannot notify individuals directly: it will notify the legal entities, who will in turn notify their beneficial owners, and a public information desk opened on 2026-08-04 (Regierung des Fürstentums Liechtenstein, 2026-08-04). That two-hop chain lands in the inboxes of Swiss and European trustees and advisers over the coming days, and it is precisely the shape a social engineer would imitate — an unexpected message about a register breach, arriving via an intermediary rather than the authority, asking the recipient to confirm who they are. Genuine and forged notifications will be in circulation in the same window.

Triage: the discriminator for recipients is direction of information flow. A genuine notification in this chain tells the recipient what happened; it does not need them to supply identity details back, because the sender already holds the relationship. A message that opens with accurate register facts and then asks the recipient to verify identity, confirm ownership or authorise a change is inverting that flow, and the accuracy of the opening facts is exactly what the stolen dataset supplies.

The Amt für Justiz has filed a criminal complaint against persons unknown, and law-enforcement authorities are evaluating digital traces in cooperation with European authorities.

Ein erster Hinweis auf ein mögliches Einfallstor des Angriffs wurde identifiziert.

Weder zu den Servern der Landesverwaltung noch zu weiteren Systemen der Landesverwaltung wurden gemäss aktuellem Kenntnisstand widerrechtliche Zugriffsversuche registriert.

Im Verzeichnis sind Name des Rechtsträgers sowie Name, Vorname, Geburtsdatum, Staatsangehörigkeit und Wohnsitzstaat der wirtschaftlich berechtigten Personen aufgeführt.

Eine Adresse oder Telefonnummer wird nicht erfasst. Ebenso werden keinerlei finanzielle Daten der Rechtsträger wie Umsätze, Vermögen oder Dividenden erfasst.

Regierung des Fürstentums Liechtenstein 2026-08-04
incident05 Aug 04:12Zmulti-sourceOpen finding ↗

2026-08-04 · view entry permalink →

HIGHNATOA1

Liechtenstein's beneficial-ownership register breached: copies of ~31,000 legal entities' records taken, and four more e-government systems pulled offline as a precaution

The Verzeichnis wirtschaftlich berechtigter Personen (VwbP, "register of beneficial owners") exists because Liechtenstein implemented the EU's 5th Anti-Money-Laundering Directive: the VwbPG has been in force since 2021, and the register records the natural persons behind Rechtsträger — companies, foundations and trust arrangements. On 2026-08-02 the government disclosed that the register had been attacked and that "Datenkopien von rund 31'000 Rechtsträgern" ("copies of data on around 31,000 legal entities") were unlawfully taken (Regierung des Fürstentums Liechtenstein, 2026-08-02). The Record and SRF both carry the same figure (The Record, 2026-08-03; SRF, 2026-08-03).

The government's own timeline is worth reading as a benchmark, because detection was human and internal rather than telemetry-driven. Unauthorised digital access occurred overnight into 2026-07-30; irregularities were noticed at the Amt für Justiz during that day; the Amt für Informatik was brought in, secured the data and took the affected system off the network the same day; the government was informed on 31 July that the attack had potentially succeeded, and the first confirmed preliminary findings arrived on the afternoon of 1 August. A crisis unit convened that evening under Head of Government Brigitte Haas and Justice Minister Emanuel Schädler, was formally confirmed on 2 August, and a media conference was announced for 2026-08-04. The government states there is no indication that data in the system was altered or deleted, and the register is unavailable to external users through the LLV.li portal.

The forensic update on 2026-08-03 is where the operationally interesting tension sits. First findings characterise the event as a targeted attack on the VwbP at the Amt für Justiz, and "Weitere Angriffe auf andere Systeme konnten nicht festgestellt werden" ("no further attacks on other systems could be established") — yet the government kept widening the shutdown: the eMWST VAT portal and the Lides electronic reporting and data-exchange platform came off the network on 31 July, and on 3 August the central account register and the central tax system Intax followed, explicitly as precautionary measures with no indication of unlawful access (Regierung des Fürstentums Liechtenstein, 2026-08-03). Law-enforcement authorities are now engaged alongside the Amt für Informatik and external partners. No initial-access vector has been published, no actor named, and no ransom demand or criminal-market offering reported.

Triage: bulk read-out of a register by an external identity is a volumetric anomaly against a stable baseline, not an indicator match — a single external session enumerating tens of thousands of entities looks nothing like the handful of lookups a legitimate professional user performs, and it is detectable with no knowledge of the attacker's tooling. The benign lookalike is a sanctioned bulk export or an integrated partner system doing a scheduled sync; those are attributable to a known principal, run on a known schedule, and appear in change records, whereas this pattern is a single principal exceeding its own historical retrieval volume by orders of magnitude within one session.

Dabei wurden Datenkopien von rund 31'000 Rechtsträgern widerrechtlich abgegriffen.

Beim Angriff auf das VwbP handelt es sich um eine Verletzung des Schutzes personenbezogener Daten gemäss Art. 33 Datenschutz-Grundverordnung (DSGVO).

Weitere Angriffe auf andere Systeme konnten nicht festgestellt werden.

Am Montag, 3. August 2026, folgten zusätzlich das Zentrale Kontenregister sowie das zentrale Steuerfachsystem Intax. Es handelt sich um reine Vorsichtsmassnahmen.

Regierung des Fürstentums Liechtenstein 2026-08-02
incident04 Aug 04:48Zmulti-sourceOpen finding ↗