Budgets

Beneficial Owners Register Breach Exposes 31,000 Records

A has exposed data copies linked to approximately 31,000 legal entities after unknown attackers gained unauthorized access to the (VwbP). Authorities confirmed the cyberattack prompted an immediate response, including taking the affected system offline, launching a technical investigation, and establishing a government-led crisis team to manage the incident.

According to official information, the attackers digitally accessed the VwbP during the night of July 30, 2026. Irregularities were detected later that day by the Office of Justice, which then contacted the Office of Information Technology to investigate the incident. Based on the initial findings, the affected system was immediately secured and removed from external access while investigators began a detailed analysis.

Beneficial Owners Register Breach Confirmed After Investigation

On July 31, 2026, the government was informed that the Beneficial Owners Register breach may have been successful. The first confirmed findings from the preliminary investigation were submitted on the afternoon of August 1.

Authorities said the attackers unlawfully accessed the directory and stole data copies relating to approximately 31,000 legal entities. The Register of Beneficial Owners (VwbP) stores information about the beneficial owners of companies, foundations, and trusts.

Officials stated that the register has been temporarily taken offline for external users through the LLV.li website while investigations continue. Based on current findings, there is no indication that any information stored in the system was altered or deleted during the incident.

Government Establishes Crisis Team

Following confirmation of the incident, the government convened a crisis team on the evening of August 1, 2026. The team immediately began its work and was formally confirmed on August 2.

The crisis team is led by Prime Minister Brigitte Haas and Justice Minister Emanuel Schädler. According to the government, its priorities are to fully investigate the incident, inform affected individuals, and implement appropriate countermeasures.

GDPR Data Breach Notification Process Underway

Authorities confirmed that the incident qualifies as a data breach involving personal information under Article 33 of the General Data Protection Regulation (GDPR).

The crisis team said it is working to notify affected individuals in accordance with Article 34 GDPR as quickly as possible. A central information point is also being established to respond to questions from those impacted by the breach.

What Is the Register of Beneficial Owners?

The Register of Beneficial Owners (VwbP) was established to support money laundering prevention and combat terrorist financing. It contains information identifying the beneficial owners of legal entities, including companies, foundations, and trusts.

The register operates under the Law on the Register of Beneficial Owners of Legal Entities (VwbPG), which came into force in 2021 to implement the requirements of the 5th EU Anti-Money Laundering Directive.

Authorities continue to investigate how the unauthorized access occurred and whether additional measures will be required to strengthen the security of the register. At this stage, officials have confirmed only that data copies were accessed and that there is currently no evidence suggesting records within the system were modified or deleted.

Source

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button