Earlier this year, cyber attackers hacked Liechtenstein’s national register of beneficial owners and stole records covering 31,000 legal entities. The database existed for a specific reason: to identify the people who ultimately own and control companies, even when layers of corporate structures might otherwise obscure those relationships.
The attackers did not demand a ransom. They just took the information.
The incident illustrates a larger vulnerability organizations and businesses often overlook: sensitive information does not exist only within the systems an organization controls. Companies tend to evaluate privacy and security by asking what information they disclose and how they protect their own networks.
An adversary starts from a different place.
They ask where the information exists: government registries, regulatory filings, vendors, financial institutions, email accounts and other third parties. Then they look for the breadcrumbs connecting those sources.
That perspective comes naturally to intelligence operators because they think about information exposure in operational terms. Establishing cover identities or companies requires understanding how seemingly insignificant data points can reveal a relationship someone intended to keep private. A reused phone number, an email address, an IP address, a personal connection or a public record can provide the first link in a much larger chain.
True anonymity is extraordinarily difficult. Creating layers of separation, or “cutouts,” can make relationships harder to identify, and many legitimate reasons exist for doing so, from limiting liability to protecting assets. But every interaction with the outside world can leave a breadcrumb.
The Liechtenstein breach demonstrates the same problem on a much larger scale. Regulations designed to increase financial transparency concentrated valuable information in a centralized system. That aggregation made the database useful to regulators and financial institutions, but it also made it an unusually valuable target.
The information itself can have value to numerous actors. A state intelligence service could use ownership records to identify relationships or potentially expose intelligence operations. Criminal hackers could combine the data with other sources to identify more promising financial targets. Competitors could seek commercially valuable information. Data brokers and other third parties could use individual data points to construct much larger profiles.
That is why Legalis approaches information risk from a 360-degree perspective: What information are you trying to protect? Where does it exist? Who would want it? How could they obtain it? What could they do with it? And what happens if it becomes public?
The answer is not simply another compliance review. It is adversarial red teaming, examining the matter from the perspective of someone actively looking for weaknesses, combined with contingency planning.
Organizations should examine themselves the way an intelligence officer, investigator or sophisticated adversary would. They should test not only their own systems but the external information environment surrounding them, and prepare for the possibility that a third party they cannot control will eventually be compromised.
The lesson from Liechtenstein is that privacy cannot depend entirely on someone else keeping a database secure. Prevention matters, but preparation matters too. Understanding where exposure can occur gives organizations the opportunity to reduce vulnerabilities and, equally important, have a plan for what happens when something they intended to keep private is no longer private.