Liechtenstein has identified a potential entry point used in a recent cyberattack that compromised economic data, according to government officials. The attack targeted the country’s registry of economically entitled persons, known as the VwbP, which was accessed at a high technical level, the government stated on Tuesday. The principality disclosed the cyberattack on Sunday, though the perpetrators remain unidentified. Investigations are ongoing. The initial findings indicate that the registry was attacked independently. According to preliminary results, the breach involved a highly sophisticated assault on a complex security structure. For safety reasons, additional sensitive data have been temporarily removed from online access. According to Fabian Schmid, head of the Office for Information Technology, the entry point was the portal used for recording entries into the VwbP. Based on preliminary findings, the attackers created access to this portal. Over several hours, they made individual queries on 31,000 entries related to companies, foundations, and trusts. Why this did not trigger an alert is under investigation, Schmid noted. The stolen data include names of legal entities and personal information such as names, birth dates, nationality, and country of residence for economically entitled individuals. Addresses, phone numbers, and financial data such as revenues, assets, or dividends were not affected by the data theft, according to official statements. The government confirmed that the attack targeted the registry of economically entitled persons maintained by the Justice Department. Forensic investigations revealed that no other systems were breached. Two systems, the central account register and the central tax system, were taken offline today as precautionary measures. There is no indication that unauthorized access occurred in these systems. All systems are now undergoing comprehensive security checks. According to the government's statement released on Sunday, an unknown perpetrator gained unauthorized digital access to the registry of economically entitled persons during the night of Thursday. Irregularities were noticed at the Justice Department on Thursday, prompting the involvement of the Office for Information Technology. This office took the affected system offline for security reasons. On Friday, the government was informed, and on Saturday, the first confirmed results of the preliminary investigation were submitted to the government. The law establishing the registry came into effect in 2021 to implement requirements set forth by the EU Anti-Money Laundering Directive. Before the abolition of banking secrecy in 2017, Liechtenstein was frequently exploited by tax evaders for their purposes. Martina Arioli, a lawyer specializing in technology and data protection, commented on the impact of the breach. She emphasized that the stolen data provide insights into the financial relationships and investments of individuals, making them sensitive information. The attack has shaken confidence in Liechtenstein's ability to manage digitalization effectively. However, she noted that the financial market in Liechtenstein benefits from trust in the confidentiality of such data. Arioli warned that the stolen data could be misused for identity theft and phishing attacks. Affected individuals must take protective measures, such as scrutinizing emails from unknown senders. It is crucial for the Data Protection Authority and affected individuals to be informed. She added that the crisis team in Liechtenstein can take several actions, including fulfilling legal obligations under the General Data Protection Regulation. They must investigate the incident thoroughly and implement necessary security measures to prevent further damage. Informing the Data Protection Authority and affected individuals is essential. The registry was managed by the government to prevent terrorist financing. Switzerland is also introducing a similar registry this year. Arioli stressed the importance of prioritizing data security. Individuals have no choice but to allow their data to be processed by authorities. Therefore, rigorous security measures must be implemented to prevent such incidents. The entire security architecture must be meticulously reviewed. The government has taken steps to address the breach, including removing sensitive data from online access and conducting thorough security assessments. The focus remains on identifying the perpetrators and preventing future breaches. The situation continues to evolve as investigations progress.
★
Neka vijesti ostanu poštene.
ObjectiveNews financiraju čitatelji i bez oglasa je – pristranost vam pokazujemo, ne skrivamo. Podržite neovisno novinarstvo za 4 €/mjesec.
Postani podupiratelj