preloader

· · digital-security digital-privacy gdpr europe compliance government data-breach aml

The Registers Europe Built for Transparency Are Turning Into the Breaches It Feared

Source: Euronews

Liechtenstein’s register of beneficial owners was built in 2021 for a straightforward reason: EU and EEA anti-money laundering rules require member and associated states to maintain a central list of the real people behind companies, foundations and trusts, so authorities and, in many cases, the public can see past shell structures to who actually controls an entity. On the night of 29 to 30 July, unknown attackers gained unauthorised access to that register and copied data belonging to roughly 31,000 legal entities before the intrusion was detected and the system was taken offline.

The transparency mandate created the target

There is a structural irony in what happened. EU AML directives, from the fourth through the sixth, exist to strip away financial secrecy by forcing exactly this kind of centralisation: one database per jurisdiction holding ownership data that used to be scattered across private filings and paper records. That mandate is sound policy, but it also concentrates information that used to be expensive to assemble into a single system that is now worth attacking directly. Liechtenstein’s government has confirmed no data was altered or deleted, formed a crisis task force led by the Prime Minister and Justice Minister, and is working through notification, but the copying itself already achieved whatever the attackers wanted, since beneficial ownership data does not need to be modified to be valuable.

Why this is not a Liechtenstein-specific problem

Liechtenstein and comparable financial centres host an unusually high concentration of companies, funds and wealth management structures relative to their size, which is precisely what makes their registers attractive. Every EU and EEA state runs the equivalent system under the same directive family, interconnected through a European-level platform for cross-border access. None of the design choices that made Liechtenstein’s register a target are unique to Liechtenstein. If a national beneficial ownership register anywhere in Europe has weaker access controls, logging, or breach detection than the country assumed when it stood the system up, this incident is the clearest possible signal that gap needs finding before an attacker finds it instead.

What this means for entities with data in one of these registers

If your company, foundation, or trust structure has ownership data filed in any EU or EEA beneficial ownership register, that data’s security has always depended entirely on a government system you do not control and cannot audit. That is unlikely to change, but it does mean your own exposure assessment should account for the possibility that ownership information you consider confidential is sitting in infrastructure with a demonstrated attack surface, and plan disclosure and reputational response accordingly rather than assuming registry security is someone else’s finished problem.

If your organisation needs help assessing exposure from third-party and government-held data stores, or wants a broader review of where your compliance filings create concentration risk you have not mapped, contact Excello Digital. We help European businesses understand risk that sits in systems they never had the option to secure themselves.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!