Cyberattack on Liechtenstein's beneficial ownership register
Over the weekend, hackers breached Liechtenstein's beneficial ownership register, the Verzeichnis der wirtschaftlich berechtigten Personen (VwbP), and copied highly sensitive data relating to around 31,000 legal entities, foundations and trusts.
The timing could hardly be more relevant. Switzerland will introduce its own federal transparency register on 1 October 2026.
So, we need to talk. But not about the obvious.
Most of the attention has focused on the cyberattack itself. That is understandable. The immediate questions are how it happened, whether it could have been prevented and what needs to change.
✨ I think we are missing a much bigger point.
Every transparency register brings together highly sensitive information. Once concentrated in one place, it becomes a powerful tool for authorities and an equally attractive target for cybercriminals.
The cyberattack in Liechtenstein is also a reminder that attacks against public registers are part of today's reality. Every government establishing such a register also accepts the responsibility to protect it.
This brings me to a question that has been on my mind for some time.
Do we fully understand the value and sensitivity of the information we are concentrating in these registers?
Transparency registers were originally introduced to combat money laundering and make it harder to conceal illicit assets. At the same time, they have become part of a much broader movement towards greater transparency in international taxation through the automatic exchange of information and an increasing number of cross-border reporting obligations.
Each of these measures has its own purpose. Taken together, however, they reveal a broader trend. We continue to collect ever larger amounts of highly sensitive information.
✨ I could not help but wonder – as the famous C.B. would say, albeit in a different, but certainly no more dicey, area – whether we have lost ourselves in our obsession with collecting more and more information.
At what point do we stop asking how much more information we can collect and start asking whether we are still collecting the right information, in the right way and for the right purpose?
And to come back to the topic at hand.
Is a central transparency register really the best way to achieve all of these objectives?
Or have we become so focused on creating new registers that we no longer stop to ask whether there are better ways to achieve the same result?
Switzerland still has the opportunity to ask these questions before its own transparency register becomes operational.
.png/picture-200?_=19fcbded048)