Liechtenstein tightens security after theft of 31,000 data copies
Wednesday 19th August 2026 on 16:15 in
Austria
Liechtenstein is tightening user account verification after a hacker attack in late July in which 31,000 copies of data from companies, foundations and fiduciary arrangements were stolen, ORF reported. All checked systems are expected to be gradually brought back online in the coming weeks.
The stolen data included the names of legal entities, as well as the names, dates of birth, nationalities and countries of residence of their beneficial owners.
Liechtenstein said on Wednesday that it had comprehensively reviewed the security architecture of its register of beneficial owners. The weaknesses identified in the registration process have been documented.
Future user account verification and identity checks will be strengthened by requiring the electronic identity system, or eID, to be used first. Monitoring and detection mechanisms will also be expanded so that unauthorised access can be identified earlier.
Before the systems are restored, the Office of Information Technology said it would carry out further comprehensive, multi-stage security tests. The systems were taken offline as a precaution. The remaining tests are extensive and will take time, the statement said.
The security analysis found that the unauthorised access had been made possible by faulty logic in the permissions checks. The weakness allowed the application programming interface to be exploited through repeated individual requests in a way it was not designed to handle.