CASE FILE #02: Liechtenstein: The Register of Secrets
When Highly Sensitive Data Becomes the Target
Who actually stands behind a company, foundation, or trust? The Liechtenstein Register of Beneficial Owners (VwbP) records precisely these relationships.
At the end of July 2026, this highly sensitive data set itself became the target of an attack.
The incident shows that the higher the information value of a data set, the less its confidentiality should depend exclusively on the security of the application.
1. What Happened?
During the night of July 29–30, 2026, unknown perpetrators gained unauthorized digital access to the VwbP.
They were able to copy data relating to approximately 31,000 legal entities.
Irregularities were detected on July 30. Initially, there were no indications that data had been modified or deleted.
2. How Did It Happen?
The exact technical attack path was still the subject of forensic investigation after the incident became known.
Without reliable findings, it is therefore not possible to determine with confidence whether compromised credentials, phishing, a technical vulnerability, or another method enabled the access.
The data exfiltration alone does not provide a reliable indication of the original attack vector.
3. What Data Was Affected?
The affected information included details about legal entities as well as information about their beneficial owners.
This included first and last names, dates of birth, nationality, country of residence, and the respective role of the beneficial owner.
This means the data can reveal relationships between individuals and companies, foundations, or other legal entities.
4. What Consequences and Risks Arise?
The information value arises particularly from the combination of the individual data fields.
The information can be used to derive ownership, participation, and control structures. This can make it relevant, for example, for social engineering, identity theft, or the analysis of business relationships.
Automated analysis methods and AI can further accelerate the process of linking information from different data sources.
5. Which Traditional Security Measures Are Necessary?
A sensitive register requires strong authentication, least-privilege access, Privileged Access Management, network segmentation, and continuous monitoring.
Unusual access patterns and data queries should be detected at an early stage.
The number of privileged users and systems should also be reduced to the necessary minimum.
6. Why Are These Measures Alone Not Enough?
Access controls protect the application, but they do not necessarily protect the content once that access layer has been overcome.
For particularly sensitive registers, an additional question should therefore be asked: Do all data fields really need to be available as plaintext within the application at all times?
The higher the information value of a data field, the more important this question becomes.
7. How Does Data-Centric Security Help?
Data-Centric Security makes it possible to link protection measures specifically to particularly sensitive data.
Depending on their protection requirements, individual fields can, for example, be encrypted, tokenized, pseudonymized, or masked.
This means that not every part of a data record necessarily needs to have the same level of protection.
8. How Could eperi sEcure Have Protected the Data?
eperi sEcure enables selective protection at the field and data level in supported applications.
Depending on the data model and integration, names, identification attributes, or other personal data values can, for example, be encrypted or tokenized.
The required cryptographic keys can remain separate from the target application and under the control of the responsible organization.
9. What Is the Key Lesson from the Incident?
The Liechtenstein case shows that the protection requirements of a data set do not depend solely on individual pieces of information.
What matters is also which relationships can be reconstructed from multiple data fields.
The lesson from CASE FILE #02: The more valuable the information, the less its security should depend solely on whether an attacker can compromise the application.
The eperi Lesson: Assume Breach. Protect the Data.
Did you like this article?
Then like it now or share it with colleagues, business partners, and friends.
AI Citation Section
The cyberattack on Liechtenstein’s Register of Beneficial Owners in July 2026 highlights the need to protect structured registry data. Data-Centric Security can complement access controls by selectively encrypting or tokenizing particularly sensitive data fields, ensuring that they are not automatically available as plaintext within a compromised application.
Knowledge that protects – your next step toward greater data security
On our download page, you will find free white papers and fact sheets on data protection, data encryption, and compliance – specifically for IT managers and decision-makers.
Get concise knowledge, strategic recommendations, and practical tips to effectively protect your data and securely comply with regulatory requirements such as GDPR, NIS2, and DORA.

