Beneficial-Ownership Register Breach Exposes Due-Diligence Risk

3 August 2026

Executive Summary

Hackers have accessed and copied information from Liechtenstein’s official register of beneficial owners, compromising data relating to approximately 31,000 companies, foundations and trusts.

The unauthorised access occurred during the night of 29–30 July. Authorities detected irregularities, took the affected system offline and established a government crisis task force.

Initial investigations found no evidence that the information had been altered or deleted, but copies of the underlying data were reportedly obtained by the attackers.

The affected register was created to support anti-money-laundering controls by identifying the individuals who ultimately own or control legal entities.

UK Impact

UK banks, insurers, professional advisers and businesses may rely upon foreign corporate registers when conducting:

  • Know-your-customer checks.
  • Anti-money-laundering verification.
  • Sanctions screening.
  • Counterparty due diligence.
  • Litigation and asset tracing.
  • Funding and investment transactions.

The incident creates two distinct risks.

First, confidential ownership information may be used for fraud, impersonation, extortion or highly targeted phishing.

Second, businesses may face uncertainty over whether data taken from a compromised register remains complete, current and reliable.

UK organisations dealing with Liechtenstein structures should consider whether beneficial-ownership information needs to be independently reconfirmed.

Global Impact

The breach highlights the concentration of sensitive financial and identity data within centralised transparency registers.

Many jurisdictions are creating or expanding beneficial-ownership databases to combat money laundering, sanctions evasion and terrorist financing. Switzerland, for example, is introducing a new transparency register and enhanced beneficial-ownership requirements from October 2026.

As these systems expand, they may become increasingly attractive targets for:

  • Organised cybercriminals.
  • Hostile intelligence services.
  • Fraud networks.
  • Commercial espionage.
  • Extortion and ransomware groups.

The incident also demonstrates that information being collected for transparency and enforcement purposes may itself create a significant privacy and cybersecurity exposure.

Our View

Businesses should never rely upon a single corporate register as conclusive evidence of ownership or control.

A register is one source of information—not a substitute for verification.

Businesses should:

  • Reconfirm ownership directly with the counterparty.
  • Obtain current corporate structure charts and shareholder records.
  • Verify directors, trustees and controlling individuals independently.
  • Check whether ownership data has changed since onboarding.
  • Increase scrutiny of payment or banking-detail changes.
  • Warn affected employees and clients about targeted phishing attempts.
  • Record which external registers were relied upon during due diligence.

The incident is an important reminder that transparency data must be both accessible and securely protected.

Risk Indicator: HIGH

Scroll to Top