Switzerland’s Transparency Register Has Become a Cybersecurity Test

Swiss wealth managers are pressing for a delay after hackers copied beneficial-ownership data from Liechtenstein. The dispute is not about whether ownership should be transparent. It is about whether centralising sensitive information creates a target the state is ready to defend.

The answer

Switzerland’s proposed beneficial-ownership register would strengthen financial-crime investigations while concentrating sensitive identity and control data in one system. After attackers copied records tied to roughly 31,000 Liechtenstein entities, a defined delay is defensible only if Switzerland uses it for independent security testing, strict access controls and proven breach containment.

Switzerland’s planned beneficial-ownership register was designed to make financial crime harder. A cyberattack in neighbouring Liechtenstein has now raised a more uncomfortable question: can a transparency system protect the people it identifies?

Swiss financial intermediaries are urging the federal government to postpone the register’s planned launch on 1 October. Their concern follows an attack on Liechtenstein’s Register of Beneficial Owners, known as the VwbP, during the night of 29 to 30 July.

The attacker copied information connected to approximately 31,000 legal entities. The exposed records included names, dates of birth, nationalities and countries of residence of people behind companies, foundations and trusts.

Liechtenstein’s government said no financial information was accessed and there was no indication that records had been changed or deleted. Its authorities took the system offline after detecting irregularities and opened an investigation.

The absence of account balances does not make the breach harmless. Identity and ownership data can support targeted phishing, impersonation, extortion and social-engineering attacks. For wealthy individuals whose structures span Switzerland and Liechtenstein, the information may also reveal relationships they reasonably expected a government system to keep confidential.

A Register Becomes a Target

Switzerland’s proposed register would be far larger than Liechtenstein’s. It is expected to hold beneficial-ownership information for roughly 600,000 legal entities, nearly 20 times the number affected in the Liechtenstein incident.

The database will not be open to the public. Access is intended for designated authorities and professionals operating under anti-money-laundering obligations. Companies and other entities will have to identify the individuals who ultimately control them, including people holding at least 25 per cent of capital or voting rights or exercising control through other means.

That structure supports a legitimate policy goal. Shell companies, opaque trusts and layered ownership arrangements can hide corruption, sanctions evasion, tax crime and money laundering. A reliable register gives investigators and regulated intermediaries a clearer view of who controls an entity.

But centralisation changes the security equation.

Information that was once dispersed across registries, advisers, banks and corporate records becomes searchable in one place. That makes legitimate investigations faster. It also makes a successful intrusion more valuable.

The register is therefore not simply an administrative database. It is critical financial-security infrastructure.

The Argument Is About Readiness

The wealth managers pressing for a delay are not necessarily opposing ownership transparency. Their stronger argument is that the government should not launch a system containing highly sensitive personal information until its security controls have been tested against the threat it will attract.

Liechtenstein has turned that concern from a theoretical objection into an observed failure mode.

The relevant standard cannot be whether the Swiss register complies with a technical checklist on launch day. It must be whether the entire system can withstand sustained attacks, detect abnormal access, limit the amount of information available to any compromised account and contain a breach before an attacker extracts records at scale.

That requires more than encryption and perimeter security. It requires strict access segmentation, immutable audit logs, continuous monitoring, data-minimisation rules, independent penetration testing and rehearsed incident response. Professionals with legitimate access should see only what they need for a defined task, while unusual searches and bulk retrieval should trigger immediate controls.

The state must also be clear about notification. If information is copied, affected individuals and institutions need rapid, actionable warnings so they can strengthen authentication, scrutinise communications and protect associated structures.

Transparency and Privacy Are Not Opposites

The political risk is that the debate becomes falsely binary.

One side will argue that any delay weakens Switzerland’s response to money laundering. The other will argue that collecting ownership data creates an unacceptable privacy risk. Both positions miss the central issue.

Transparency and privacy can coexist, but only when access is purposeful, proportionate and controlled. Authorities need accurate information about who owns and controls legal entities. That does not mean every authorised user should have unrestricted visibility or that the system should retain more information than its legal purpose requires.

The better question is not whether the register should exist. It is what evidence Switzerland should demand before trusting it with data of this sensitivity.

A short, defined postponement could be justified if it is used to complete independent security testing, close identified weaknesses and publish credible assurance about access and incident controls. An open-ended delay driven by industry resistance would be harder to defend.

The Cross-Border Consequence

The incident also shows why national cybersecurity cannot be assessed in isolation.

Swiss clients frequently use Liechtenstein foundations and trusts. Banks, asset managers, fiduciaries and advisers operate across both jurisdictions. A breach in Vaduz can therefore create immediate exposure in Zurich, Geneva and beyond, even when no Swiss system has been penetrated.

Attackers do not respect the legal boundary between a registry record and a bank account. They combine information from multiple sources until they have enough context to impersonate a client, deceive an adviser or target a family office.

Switzerland’s register will enter that same cross-border threat environment. Its security model must account not only for direct intrusion, but also for how its records could be combined with leaked corporate, identity and financial data elsewhere.

The Decision Before October

The federal government now faces a narrow but important choice.

Launching on schedule would demonstrate commitment to corporate transparency, but it would also require confidence that the register can resist the class of attack Liechtenstein has just experienced. Delaying would give authorities more time to test and strengthen the system, but only if the postponement has specific security objectives and a firm endpoint.

The Liechtenstein breach does not prove that beneficial-ownership registers are a mistake. It proves that their security is inseparable from their legitimacy.

If Switzerland wants companies and wealthy individuals to disclose who ultimately controls their assets, it must show that transparency will not become exposure.

Sources

  1. Cyberattack on the VwbP: Latest InformationGovernment of Liechtenstein

    Primary authority

  2. Liechtenstein Says Hackers Accessed Information on 31,000 Legal EntitiesReuters

    News report

  3. Swiss Wealth Managers Urge Delay to Ownership Register After Liechtenstein HackFinancial Times

    Original reporting

Jonathan P. De Collibus

Jonathan co-founded Svperior in 2014 and leads its cyber practice. His work sits where adversarial pressure, technical architecture, and consequential decisions meet, with experience across clinical, financial, public-sector, and private-client systems where confidentiality, continuity, and technical correctness carry material consequences.

Cyber strategy / Adversarial assessment / Security architecture / Private systemsRead Jonathan's full biography

Need to apply this to a specific situation?

Send us the initial context. If the matter fits, we will respond directly.

Send private inquiry