Compliance
ANALYSIS: Liechtenstein’s Cybersecurity Attack Part Of Global Trend
.jpg)
The incident, as disclosed by the European principality this week, is part of a pattern that continues to put compromises to privacy high up on the private banking and wealth management agenda. We list a few recent examples of where defences were broken.
As reported here, the Liechtenstein government has disclosed a register of beneficial ownership with 31,000 legal entities was hit in a cybersecurity attack.
The episode shows how government-run registers, databases and other information sources can be targeted. This raises questions on whether the drive for transparency on beneficial ownership data can clash with security of that information.
Revenue-gathering authorities in countries that have engaged in tax disclosure pacts with Liechtenstein, such as the UK and HM Revenue & Customs, will monitor the situation.
“It is not clear how and when any information obtained from this latest data leak will be used. However, with Liechtenstein being home to many low-tax trusts, one thing we can be sure of is that HMRC will be watching developments closely," Alistair Culverwell, partner and head of tax dispute resolution, Forvis Mazars, said in an emailed statement to this news service.
The attack is a blow to Liechtenstein, a jurisdiction
that received a “Largely Compliant” rating from the OECD in
a report in June this year. The Paris-headquartered body, in
its Enhanced Monitoring Report on the Implementation of the
Standard on Transparency and Exchange of Information on
Request (EOIR), recommended that Liechtenstein should
“further strengthen” measures so that that beneficial ownership
information is available in respect of “all relevant entities and
arrangements as required under the standard.”
The OECD report made no reference to the cybersecurity angle. It
said that under new legislation, the Fiscal Authority
(Liechtenstein’s competent authority) has access to the
beneficial ownership register. The Financial Intelligence Unit,
the Financial Market Authority, the Prosecutors Office, the
Princely Court, the National Police, AML-obliged persons and the
Liechtenstein Bar Association (as a supervisory authority) also
have access to the register. Liechtenstein has taken
“comprehensive actions to address the recommendation and is no
longer required to report,” the OECD said, noting that a
“previous gap” in beneficial ownership information had been
closed by new legislation.
Besides cybersecurity attacks are data leaks including the Panama Papers and the Paradise papers episodes.
When governments enter automatic exchange of information agreements with the ostensible purpose of foiling tax evaders and illicit financial flows, cybersecurity attacks raise questions about what happens if criminals and other hostile actors break into the data "vaults". Some countries, such as European Union member states, are under the General Data Protection Regulation (GDPR) powers that went into effect in 2018 (the UK remains under this, even after leaving the EU). Certain states in the US, such as California, have a version of GDPR, while the US as a whole so far doesn’t have this at a federal level. (This recent controversy about New York City Mayor Zohran Mamdani's database on "pied à terre" homes also raises questions about BO information.) Regulations elsewhere in the world are patchy.
Liechtenstein has already acknowledged the latest attack is a personal data breach under GDPR rules.
The editor of this news service examined a list of major breaches and attacks on government data sources over the past six months. Here are examples. Some of the cases are still live and haven’t been fully resolved.
UK
The UK Companies House WebFiling case, which happened
in March. A vulnerability in CH’s WebFiling service, traced
to an October 2025 system update, let logged-in users view, and,
under some conditions potentially amend another
company's dashboard. This enabled changes to be made to data such
as directors' home addresses, dates of birth and emails. The
vulnerability was discovered between 12 and 13 March by a
corporate services researcher. Companies House took WebFiling
offline on 13 March and restored it on 16 March. CH said no
paswords, identity-verification data or filed documents had
been altered.
The Netherlands
On 19 March, the Ministry's ICT security team detected
unauthorised access to systems. A tip-off was received by
a third party who alerted the Ministry to suspicious
activity. Affected systems, including a Treasury banking portal,
were deliberately taken offline on 23 March to stop data being
exfiltrated.
Tax collection, customs and income-linked subsidy systems that handled more than 9.5 million income tax returns a year were not affected, reports said. The breach was reported to the Dutch Data Protection Authority over possible exposure of employee data. No group has claimed responsibility.
The Netherlands and EU
The European Commission, the Dutch Data Protection Authority
and Judicial Council were hacked. Work-related names, emails and
phone numbers were accessed in the Dutch incident, while the
Commission contained its breach within nine hours.
Sweden
The cybercrime group ByteToBreach reportedly stole Swedish
government data from its E-Gov platform.
Spain
Check Point Research identified a malicious email campaign
impersonating the Spanish tax authority, Agencia Tributaria
(AEAT), with a spoofed email sent to a Spanish industrial
company, carrying a trojan-downloader attachment, reports
said. This did not breach AEAT's own systems, but it was
part of a wider range of attacks.
General
Comparitech recorded 187 ransomware attacks on government
agencies worldwide in the first half of this year, rising 13 per
cent from the second half of 2025. Several of these attacks hit
agencies that hold tax and business-registration data at the
state/municipal level.