Around July 29, 2026, unknown group of attackers gained unauthorized access to Liechtenstein’s Register of Beneficial Owners.
They copied records of approx. 31K+ legal entities, including companies, foundations, and trusts ([1]).
For U.S. families and family offices that hold assets through those structures (including crypto), this is not a tale about how European compliance works.
It is a personal security event, and the next wave of attacks could happen by email, phone, and video call.
This article explains what information was exposed and who may be affected.
It also explores how ordinary data can could become more sensitive when combined with information available through US public databases (e.g., ADV filings submitted by investment advisers to the SEC).
With today’s advanced AI-powered search and pattern-recognition tools, bad actors can uncover insights that would have been difficult to identify just a few years ago.
Finally, it talks about the steps that families with asset protection trusts in Liechtenstein,Cook Islands, Nevis, and other trust-register jurisdictions should consider reviewing now.
This article also touches upon a question that offshore asset protection trust attorneys are increasingly asked after incidents like this: if trust assets are compromised as part of a cyberattack (e.g., account takeover involving a trust bank account or cryptocurrency wallet,), who bears the loss?
Many readers would be surprised to learn that many trust agreements are either silent on this issue or have provisions, placing the risk of loss on someone other than the trustee.
For a more detailed discussion of that issue, see our article, “AI Cyberattacks and Asset Protection Trusts: Who Bears the Loss?“
Key takeaways
- Liechtenstein’s government confirms that data on more than 30K+ legal entities was copied without authorization.
- The Five Eyes cyber agencies, including the NSA, said on June 22, 2026 that frontier AI is changing offensive cyber capabilities – “The timeline is not years, it is months.”
- U.S.families and invididuals should assess their exposure and upgrade cybersecurity.
What was taken
According to the Liechtenstein government, compromised records included names of legal entities and identifying information about their beneficial owners, including names, DOBs, nationalities, countries of residence, etc. ([1]).
The government’s incident response review determined that intrusion was made possible by a flaw in the system’s authorization controls ([2]). Officials described the incident as highly sophisticated attack. ([3]).
For families that use offshore structures, the significance of the breach is beyond the loss of data.
Whoever got these records may now have verified information of who owns or controls thousands of private wealth structures (together with personal information that could be used in phishing, social engineering and impersonation).
How Cybercriminals Build a Targeted List
Beneficial ownership data becomes far more sensitive when it can be matched with info available from other public sources.
For example, every U.S. investment adviser registered with the US Securities and Exchange Commission has to file Form ADV. Much of the information disclosed in those filings is publicly available through SEC’s portal ([4], p. 12).

The issue is that Form ADV shows not only the identity of an advisory firm and its key personnel, but also the firm’s AUM, approx. number of client accounts, and portion of assets that attributed to non-U.S. clients ([5], pp. 13-14).
When combined with beneficial ownership records, this information can provide a road map for cybercriminals.
Recent cyber warnings (e.g., NSA Five Eyes report) and the fallout from the Liechtenstein breach highlight how investment advisers could become attractive targets for sophisticated cyberattacks.
Aggregated public records can identify HWN, where they operate, and professionals who advise them.They could also trace the entities through which they hold and manage assets.
That, in turn, could increase the risk of targeted phishing, business email compromise, impersonation, and other social engineering attacks.
FinCEN has already warned that criminals combine generative-AI images with “stolen personally identifiable information” to build fake identities that pass customer identification and due diligence controls ([7], pp. 2–3).
The FBI’s Internet Crime Complaint Center received 1,008,597 complaints in 2025 with $20.877 billion in reported losses; personal data breach alone accounted for $1.31 billion; business email compromise was apprx. $3.05 billion ([8], pp. 6–8).
Five Eyes Warning
Liechtenstein breach did not occur in isolation.
Just weeks before news of the incident emerged – on June 22, 2026, the NSA and its counterparts in the United Kingdom, Canada, Australia, and New Zealand issued a joint statement on artificial intelligence and cyber risk ([9]).

“Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months.” — Five Eyes Cyber Security Agencies Statement, June 22, 2026 ([9])
Five Eyes agencies urged organizations saying “Breaches will occur. Preparedness helps you contain them quickly and prevent escalation into major operational and financial crises.”
The guidance was even more than blunt: “Test response plans, train and prepare teams, and assume breaches will occur” ([9]).
For many families with domestic/offshore asset protection trusts, that advice is no longer theoretical.
If the organization never rehearsed how to verify and respond to such a request, it could be exactly the type of target the Five Eyes warning was describing.
Family offices, trustees, and advisers should consider running tabletop exercises and updating their business continuity and incident response plans. This could help to address AI-enabled fraud and attacks.
Cook Islands, Nevis, Liechtenstein: what to review in an existing offshore trust
Liechtenstein register exists because anti-money-laundering rules now require most jurisdictions to record who stands behind a structure ([1]).
The lesson is not limited to Liechtenstein.
Families with offshore structures in foreign jurisdictions (Cayman Islands, Cook Islands, Nevis, Jersey etc.) should assume that similar information exists in trustee records, banking files, and due diligence databases.
Each database has valuable identity information. Each can become a target. Choose your jurisdiction wisely.
The takeaway is not to abandon offshore planning. It is to choose the jurisdiction, trustee, and structure carefully. You should understand that cyber risks are now as important as legal, creditor and tax risk.
In our experience, many U.S. domestic and offshore trusts were drafted long before today’s cyber threats emerged, i.e., the Five Eyes’s Report.
If the trust agreement is silent or unclear on cyber risk and loss allocation, a fresh review of the trust agreement would not hurt.
Depending on the trust instrument and governing law, cyber-related gaps can often be addressed through amendments, trust protector action, or other mechanisms.
If a structure no longer serves its purpose, orderly wind-down could be appropriate.
U.S. tax and reporting consequences should be reviewed before any assets are moved. U.S. tax and reporting obligations should be reviewed before any assets are moved.
When a trustee loses the money: who bears the loss
If a trustee wires trust assets to a fraudster impersonating a settlor, protector, or adviser, the first document to read is the trust agreement.
Many clients are surprised to learn that, for example, New York Banking Law § 100 authorizes a trust company to act in a fiduciary capacity and to “receive, take, manage, hold and dispose of” trust property according to the terms of the trust.
The statute, however, DOES NOT expressly say that the trustee must protect (or has a duty to safeguard) trust assets from foreseeable account takeovers, deepfakes, or other cyber fraud schemes. There is no implied duty to safeguard trust’s assets under Section 100 of NY Banking Law.
That should raise an obvious question: if New York does not clearly address those duties by default, what exactly do the default rules say in Delaware, South Dakota, the Cook Islands, Nevis, or another offshore jurisdiction?
From our experience, most settlors and beneficiaries have no idea.
To be sure, trust statutes establish guardrails. Delaware, for example, allows a trust instrument to modify a fiduciary’s powers, duties, standard of care, indemnification rights, and liability ([15], § 3303(a)).
New York goes even further. Under New York E.P.T.L. § 11-1.7, a provision that relieves a fiduciary from liability for failing to exercise reasonable care, diligence, and prudence is void as against public policy ([16]).
These statutory frameworks provide useful guidance.
However, they don’t fully address a critical modern question – does a trustee have affirmative duty to protect trust assets from AI-enabled fraud, account takeovers, or other cyber threats? And if those safeguards fail, is the trustee responsible?
That is why families should not rely on default rules.
If the settlor expects the trustee to follow specific cybersecurity procedures or pick-up the risk of loss due a cyber-event like an account-takeover, those expectations should be written directly into the trust agreement.
If your trust agreement does not address cybersecurity risks, Dilendorf Law Firm can help evaluate whether an amendment, decanting, or other trust modifications may be appropriate.
Likewise, if your trust has suffered losses as a result of a cyber incident, account takeover, or related fraud, please contact us to discuss your potential claims and evaluate your legal options.
What to do in the first 30 days
- Confirm your exposure. Liechtenstein instructed legal entities to notify their beneficial owners in writing, with letters going out since August 4, 2026; questions may be directed to the Office of Justice at vwbpfragen@llv.li ([1]). Ask your trustee or foundation council for a copy of the notice and a list of the data fields involved.
- Upgrade Security. CISA advises highly targeted individuals to use phishing-resistant FIDO security keys or passkeys. Review CISA guidance for more personal cybersecurity tips ([10]).
- Account Security. Increase security controls for bank and investment accounts. ,
- Review the trust instrument. Review trust agreements to understand trustee’s cyber responsibilities and who bears the risk of loss from an account takeover.
How Dilendorf Law Firm helps
Dilendorf Law Firm advises HWN individuals and family offices on offshore and domestic asset protection trusts. The firm reviews and updates existing trust structures to address modern cyber risks.
Where appropriate, it also represents settlors and beneficiaries in claims involving trustee misconduct, negligence and breach of fiduciary duties that resulted in cyber-related losses.
The firm helps HWN clients, family offices and investment managers prepare for cyber threats through tabletop exercises and incident-response planning.
Following a cyber incident, the firm works with the FBI’s IC3 and retired law enforcement cyber specialists on evidence preservation, fund recovery efforts, and communications with financial institutions and trustees.
If trust assets were transferred as a result of an account takeover, fraudulent instruction, or other cyberattack, and you believe the loss resulted from a trustee’s negligence, Dilendorf Law Firm can evaluate potential claims against the trustee and other responsible parties.
Contact Us
To discuss an offshore or domestic asset protection trust, a breach notice, or losses involving a trustee or custodian, contact Max Dilendorf at +1 212 457 9797 or info@dilendorf.com. You may also reach us through our contact page.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Frequently asked questions
How do I find out whether my family’s structure was affected by the Liechtenstein breach?
Ask the entity’s trustee, foundation council, or registered agent. The Liechtenstein government has directed legal entities to inform their beneficial owners of the personal data breach, with letters going out since August 4, 2026. It operates a dedicated inquiry address, vwbpfragen@llv.li, staffed by the Office of Justice ([1]). Because deleted entities were also affected, structures wound up years ago may still be included ([1]).
What personal information did the attackers get?
The government states the copied data includes the legal entity’s name and, for each beneficial owner, the role held, surname, first name, date of birth, nationality or nationalities, and country of residence ([1]). There is no indication that records were altered or deleted, and the government has not stated that the data has been publicly released ([1]).
How could criminals use a beneficial owner list against me?
The most likely uses are impersonation and social engineering. FinCEN reports that criminals pair stolen personally identifiable info with AI-generated data to create fake identities that could defeat bank verification controls ([7], pp. 2–3). Knowing the exact entity a family controls also makes a fraudulent trustee, banker, or lawyer email far more convincing. Business email compromise produced $3.05 billion in reported U.S. losses in 2025 ([8], p. 8).
Should I update, move, or terminate my Cook Islands or Nevis trust after the Liechtenstein breach?
Not automatically, and not without reading the deed first. The breach shows that identity data behind offshore structures is a target. Practical question becomes is whether your instrument tells the trustee how to verify instructions and what to do after a breach notice. Depending on the deed and the governing law, trust agreement could be fixed by amendment, protector action, decanting, etc.; a wind-down is a last resort that must be coordinated with U.S. tax and reporting obligations. Offshore asset protection trust attorney should review the instrument before any asset moves. Contact Dilendorf Law Firm for a consultaiton.
Can I sue my offshore trustee if it wired trust funds to a fraudster?
Possibly, depending on the facts. The trust instrument and governing law decide most of these cases. Delaware lets an instrument vary a fiduciary’s “standard of care, rights of indemnification and liability” but not excuse “wilful misconduct” ([15]), and New York voids clauses that exonerate a fiduciary “from liability for failure to exercise reasonable care, diligence and prudence” ([16]). Offshore statutes often allow broader exculpation, and Delaware bars claims one year after an adequate trustee report ([17]), so timing and evidence preservation matter.
Is my U.S. beneficial ownership information also exposed?
Not through FinCEN’s register, based on current rules. FinCEN’s March 2025 interim final rule, finalized on August 11, 2026, exempts all entities created in the United States and their beneficial owners from reporting; only certain foreign-formed companies registered to do business in a U.S. state remain reporting companies ([12]). Your exposure in the United States comes mainly from public adviser filings and from your own advisers’ systems, not from a federal ownership database.
What are the warning signs of an attack that uses this data?
Watch for unexpected contact that references your specific foundation, trust, or company by name; requests to change wire instructions or add a signatory; new devices or logins on email and brokerage accounts; and a mobile phone that suddenly loses service, which can signal a number-porting attack. CISA recommends a carrier PIN precisely because porting a number is “a critical step in countering” account takeover ([10]).
What should I do in the first 48 hours after a suspicious wire or account change?
Contact the bank immediately and request a recall of the funds, then file a complaint at ic3.gov with the full transaction details ([8], p. 17). Complaints that meet IC3’s thresholds are routed to the Recovery Asset Team, and for foreign wires the International Financial Fraud Kill Chain is coordinated through FinCEN’s Rapid Response Team and FBI legal attachés ([13]). Preserve emails, call logs, and instruction records before anything is deleted.
What is a tabletop exercise and why would a family office need one?
A tabletop exercise is a facilitated discussion that walks decision-makers through a realistic incident, tests who does what, and exposes gaps before a real event. The Five Eyes agencies told organizations to “Test response plans, train and prepare teams, and assume breaches will occur” ([9]). CISA’s free packages include template objectives, scenarios, and discussion questions for ransomware, phishing, and insider threats ([11]). Dilendorf Law Firm runs these exercises for family offices and investment managers and tailors the scenarios to the family’s actual structures and counterparties.
When should I involve a lawyer?
Involve counsel as soon as you receive a breach notice, before any funds move. A lawyer can coordinate the response with trustees in multiple jurisdictions, preserve evidence in a form law enforcement can use, manage the IC3 filing and bank recall requests, and evaluate whether a bank, custodian, or trustee that honored a fraudulent instruction may bear responsibility, which depends on the facts and the governing agreements. Dilendorf Law Firm coordinates with IC3 and retired cybersecurity law enforcement specialists in these matters.
Sources
[1] Government of the Principality of Liechtenstein, “Cyberattack on the VwbP: latest information” (updated August 2026). https://regierung.li/text/16188/topics
[2] Government of the Principality of Liechtenstein, press release, “Following the cyberattack: security analyses completed” (August 19, 2026). https://www.regierung.li/medienportal-medium/16444/234754/0/medienmitteilung
[3] Government of the Principality of Liechtenstein, press release, “Krimineller Angriff auf das VwbP: Potenzielles Einfallstor identifiziert” (August 4, 2026). https://www.regierung.li/medienportal-medium/16182/234671/medienmitteilung
[4] U.S. Securities and Exchange Commission, Form ADV General Instructions, SEC 1707 (07-24), p. 12. https://www.sec.gov/files/formadv-instructions.pdf
[5] U.S. Securities and Exchange Commission, Form ADV Part 1A, Item 5.F, pp. 13–14. https://www.sec.gov/files/formadv-part1a_1.pdf
[6] 17 C.F.R. § 275.202(a)(11)(G)-1, Family offices (Legal Information Institute, Cornell Law School). https://www.law.cornell.edu/cfr/text/17/275.202(a)(11)(G)-1
[7] FinCEN, Alert FIN-2024-Alert004, “FinCEN Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions” (November 13, 2024), pp. 2–3. https://www.fincen.gov/system/files/shared/FinCEN-Alert-DeepFakes-Alert508FINAL.pdf
[8] FBI Internet Crime Complaint Center, 2025 Internet Crime Report, pp. 6–8, 17. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[9] National Security Agency, “Five Eyes Cyber Security Agencies Statement” (June 22, 2026). https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/4523810/five-eyes-cyber-security-agencies-statement/
[10] Cybersecurity and Infrastructure Security Agency, “Mobile Communications Best Practice Guidance” (December 18, 2024). https://www.cisa.gov/sites/default/files/2024-12/guidance-mobile-communications-best-practices.pdf
[11] Cybersecurity and Infrastructure Security Agency, “CISA Tabletop Exercise Packages.” https://www.cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages
[12] FinCEN, “Beneficial Ownership Information Reporting” (final rule issued August 11, 2026, effective August 14, 2026). https://www.fincen.gov/boi
[13] FBI Internet Crime Complaint Center, “International Financial Fraud Kill Chain Process.” https://www.ic3.gov/Outreach/Brochures/IC3-FFKC_International.pdf
[14] FinCEN, “FinCEN Issues Final Rule to Postpone Effective Date of Investment Adviser Rule to 2028” (December 31, 2025). https://www.fincen.gov/news/news-releases/fincen-issues-final-rule-postpone-effective-date-investment-adviser-rule-2028
[15] 12 Del. C. ch. 33, Administrative Provisions, §§ 3302(e), 3303(a) (Delaware Code Online). https://delcode.delaware.gov/title12/c033/index.html
[16] N.Y. Estates, Powers and Trusts Law § 11-1.7 (New York State Senate). https://www.nysenate.gov/legislation/laws/EPT/11-1.7
[17] 12 Del. C. §§ 3585–3586, Limitations on actions against trustees (Delaware Code Online). https://delcode.delaware.gov/title12/c035/sc07/index.html

