
The Swiss Transparency Register Goes Live 1 October 2026: 500,000 Companies, and One More Field Than the Register Just Stolen
By, zero-adm
- 3 Aug, 2026
- 18 Views
From 1 October 2026, more than 500,000 Swiss companies must file with a federal register the identity of their beneficial owners: first name, surname, date of birth, nationality and residential address. Eight weeks earlier, in the night of 29 to 30 July, an intruder copied the same class of data from Liechtenstein’s equivalent register: some 31,000 legal entities. The Swiss register asks for one field the stolen one never held: the home address.
The Swiss transparency register is the federal, non-public list of the natural persons who really control a Swiss company. It is not a surprise sprung by Bern: it is the Transparency of Legal Entities Act (LTPG), whose entry into force the Federal Council confirmed on 12 June 2026. What is new is the timing it now arrives with.
What happened to Liechtenstein's register?
In the night of Wednesday 29 to Thursday 30 July 2026, an unknown perpetrator gained unlawful digital access to the Verzeichnis wirtschaftlich berechtigter Personen (VwbP), the beneficial-owners register held by Liechtenstein’s Office of Justice, and copied data relating to roughly 31,000 legal entities: companies, foundations and trusts.
One clarification most of the press got wrong, and it matters: 31,000 is legal entities, not people. One entity can have several beneficial owners, and one person can sit behind many entities. How many individuals are affected has never been published by anyone.
Five fields were taken: surname, first name, date of birth, nationality and country of residence. We know this with unusual precision because Art. 4(1)(a) of the Liechtenstein statute lists exactly those five fields and nothing else. The register held no street addresses, no ID or passport copies, no account numbers and no financial data. The law itself caps what could have come out of it.
The sequence, per the Principality’s two government releases: irregularities noticed at the Office of Justice on 30 July, the system taken off the network the same day, the government informed on 31 July, first investigation results on the afternoon of 1 August, a crisis unit convened that evening under head of government Brigitte Haas and justice minister Emanuel Schädler, and the first public statement on 2 August at 18:34. The government classifies the incident as a personal-data breach under Art. 33 GDPR, which applies in Liechtenstein through the EEA agreement, and is notifying data subjects under Art. 34.
As of 3 August there is no ransom demand, no claim of responsibility, no dark-web listing or sale offer, and no indication that data was altered or deleted. Nobody has attributed the attack. On 3 August the government added that forensics indicate a targeted attack on the VwbP alone, while four further systems were taken offline as a precaution: the eMWST VAT portal and the Lides platform on 31 July, the central account register and the Intax tax system on 3 August. They were switched off out of caution, not because they were breached.
A government press conference was announced for 4 August. Everything above is current as of 3 August; if you are reading later, check what has moved.
Why does this concern a Swiss company with nothing in Liechtenstein?
Because Switzerland is about to switch on the same kind of infrastructure, at vastly greater scale, in eight weeks.
On 1 October 2026 the LTPG and the revised Anti-Money Laundering Act enter into force. They create the federal transparency register, held by the Federal Department of Justice and Police and filed through the EasyGov.swiss portal. According to EasyGov itself, over 500,000 companies will be legally required to submit details of their beneficial owners.
Who must file: corporations, limited liability companies, partnerships limited by shares, cooperatives, SICAVs, SICAFs and limited partnerships for collective investment. Foreign entities are caught too, where they have a registered Swiss branch, their effective place of management in Switzerland, or own or acquire Swiss real estate. Listed companies, associations, foundations and sole traders are out of scope.
Here is the difference worth stating honestly: Liechtenstein’s register also covered foundations and trusts; the Swiss one does not. The two lists are not identical. But the Swiss register adds a field the Liechtenstein one never had: the beneficial owner’s residential address, and asks for it from half a million companies instead of thirty-one thousand entities.
The deadlines are already set, and staggered:
| Category of entity | Filing deadline |
|---|---|
| Beneficial owners already in the Commercial Register as partners or officers | 2 years → 30 September 2028 |
| Corporations subject to ordinary audit | 3 months → 31 December 2026 |
| Other entities subject to ordinary audit | 4 months → 31 January 2027 |
| Corporations not subject to ordinary audit | 5 months → 28 February 2027 |
| Other entities and foreign entities | 6 months → 31 March 2027 |
| Changes to a Commercial Register entry | 1 month from the amendment |
| Newly incorporated entities | 1 month from registration |
The Swiss register is not public either: access is limited to Swiss authorities and to financial intermediaries and advisers subject to anti-money-laundering obligations, via EasyGov or a secure interface authorised in advance by the Federal Office of Justice.
Which is precisely what was said of Liechtenstein’s register too: access restricted by statute to authorities, banks, AML-obliged parties, and third parties only on a reviewed request. It was not an open list on the internet. It was copied anyway.
This is not a data-sovereignty problem — and that is what makes it interesting
The comfortable reading of this story is: see, this is why you keep data at home. It does not work here, and it is worth saying why.
Liechtenstein’s register was run by Liechtenstein, on Liechtenstein soil, by a Liechtenstein authority, with access limited by law. It ticked every box we normally file under “sovereignty”, ourselves included, when we wrote about digital sovereignty in Switzerland. The data left anyway.
Which means the risk here does not come from where the data sits, or who hosts it. It comes from concentration: a legal obligation gathers, into one system, the identity of the people controlling tens or hundreds of thousands of structures, and not one of the obliged parties has any say in how that system is defended.
It is a category of risk that is mapped nowhere in most companies, because it does not look like an IT risk. It looks like paperwork. With a supplier you run due diligence, negotiate a contract, ask for certifications, and can walk away. With a mandatory register you do none of that: you simply hand it over. There is no alternative to buy, no contract to renegotiate, no exit plan.
This is not an argument against transparency registers, which exist for a serious reason: making it harder to hide dirty money behind chains of companies. It is an argument for taking seriously the one part of the problem you actually control: how your data gets in there, and who in your organisation holds the key to that door.
What to do now
- Decide who files, before the window opens. Between October and December, somebody in your company or your firm will open an EasyGov account and upload the identity of your controlling shareholders. Settle now: which named person holds those credentials (not a shared
admin@mailbox), whether that account has two-factor authentication, whether the same login also opens other federal portals, and who gets alerted if it is used out of hours. Deciding this in September costs an hour. Deciding it in January, after a filing account has been phished, costs a client. - Write down your real deadline, not “October”. Find your row in the table above. A corporation subject to ordinary audit has until 31 December 2026. Three months, holidays included. A foreign entity with a Swiss branch has until 31 March 2027. These are different dates, and whoever conflates them finds out late.
- Assemble the data before October, not during. Structures with intermediate companies also need the ownership chain, not just the final name. Reconstructing it takes documents that usually live with a trustee, a notary, or in a cupboard. This is the piece of work that blows deadlines.
- If you have Liechtenstein structures, do two things this week. Ask in writing, either your trustee, or the Office of Justice information point at
vwbpfragen@llv.li— whether your entities are among the ~31,000 and when data subjects will be notified. Keep the answer. Then warn the named individuals about the right risk: what is out there is a name, a date of birth, a nationality and a country of residence: a perfect kit for a plausible phone call. One short message: neither the Office of Justice nor your trustee will ever call, email or message you to confirm identity details, transfer anything, or “reactivate” an entry. Every such contact is fraud. - Map the portals that share a supplier. This is the one transferable technical lesson, and it is not “patch faster”. List every external portal your company logs into: VAT, tax, commercial register, social insurance, FINMA, customs, EasyGov — and mark which ones run on the same platform or share one set of credentials. Liechtenstein took four government systems offline in four days, and two of them ran on the same supplier’s platform as the register that was hit. Your blast radius is defined by shared platforms, not by shared networks — and in most companies that map does not exist.
Frequently asked questions
Does my company have to file its beneficial owners with the Swiss register?
Yes, if it is a corporation, a limited liability company, a partnership limited by shares, a cooperative, a SICAV, a SICAF or a limited partnership for collective investment. Also if it is a foreign entity with a registered Swiss branch, effective management in Switzerland, or Swiss real estate. Listed companies, associations, foundations and sole traders are excluded.
What data must be reported?
First name and surname, date of birth, nationality and residential address of the natural person exercising control, plus the ownership chain where intermediate companies sit between you and them.
Will the Swiss register be open to anyone?
No. Access is reserved to Swiss authorities and to financial intermediaries and advisers subject to anti-money-laundering obligations, through EasyGov or a secure interface authorised by the Federal Office of Justice.
Did the Liechtenstein breach expose addresses or banking data?
No. The Liechtenstein statute provides five fields for a natural-person beneficial owner: surname, first name, date of birth, nationality, country of residence — and nothing else. No home addresses, no documents, no accounts or asset values.
I am a Swiss company with no Liechtenstein ties: was I affected?
No. No Swiss register, authority or system was touched. Swiss exposure is indirect and concerns those who administer, advise or bank Liechtenstein structures. The reason this story concerns you is the 1 October deadline, not the breach.
What cannot be rotated
After an incident you change passwords, revoke tokens, reissue keys. It is why most breaches are eventually absorbed: nearly everything that gets stolen can be replaced.
Beneficial-ownership data cannot. A date of birth does not rotate. Neither does a nationality. A home address changes two or three times in a lifetime, and never because an office asked it to. What left Vaduz on 30 July will still be accurate in ten years — which is why the absence of a ransom demand is not good news. It only means whoever copied it is in no hurry.
In eight weeks Switzerland starts collecting the same material from half a million companies, with the home address on top. That the register exists is not in question, and should not be. What is still in question, and only for a few more weeks, is who in your company will hold the keys to that door — and whether that decision will be yours, or one you find already made.
Sources
- Government of the Principality of Liechtenstein, releases of 2 and 3 August 2026, Unberechtigter Zugriff von Dritten auf Verzeichnisdaten and Erste Erkenntnisse: Gezielter Angriff auf das Verzeichnis wirtschaftlich berechtigter Personen
- VwbPG — Liechtenstein’s beneficial-owners register act, Art. 4(1)(a) (gesetze.li)
- SRF, Cyberangriff auf Wirtschaftsdaten im Fürstentum Liechtenstein, 2 August 2026
- Netzwoche, Hacker kopieren sensible Daten von Liechtensteiner Justizbehörde, 3 August 2026
- finews.ch, Cyber-Gau im Fürstentum Liechtenstein, 3 August 2026
- Reuters (via Euronews and SWI swissinfo.ch), 3 August 2026
- EasyGov.swiss — Transparency register, Swiss Confederation portal
- Lenz & Staehelin, New Legal Entities Transparency Act to enter into force on 1 October 2026
- laRegione, Nuove norme svizzere anti-riciclaggio con registro della trasparenza in vigore dal 1° ottobre
Recent Posts
- The Swiss Transparency Register Goes Live 1 October 2026: 500,000 Companies, and One More Field Than the Register Just Stolen
- Third-Party Breaches Hit 48% in 2026: EY and a Swiss Fiduciary Leaked the Same Way
- AI Agent Security in 2026: 78% of Firms Already Hit — and Most Can’t Explain Why
- Chat Control: More MEPs Voted No Than Yes, and It Passed Anyway
- Time-to-Exploit Just Went Negative: Why Patching Is No Longer Enough in 2026
Category
- Cyber Security (93)
- Vulnerability Assessment (71)
Newest Posts
All Tag
2025 AI Automation Awareness Beneficial Ownership Business CISO Compliance Cybercriminals CyberSecurity Academy Cybersecurity Awareness CyberSecurityRating Dataprotection EU AI Act Future GDPR Malware nFADP NIS2 nLPD Phishing Privacy Ramsonware Ransomware Supply Chain Switzerland Threat Intelligence Transparency Register Treat Detection Vulnerability Assessment Vulnerability Management Zero-Day Zeroedge Academy
