D1 Sanctions
Sanctions is not yet covered for this jurisdiction in this report.
Liechtenstein is a MONEYVAL-assessed EEA/EFTA state (not an EU member) whose Due Diligence Act and Financial Market Authority (FMA) govern AML/CFT for banks, TCSPs, foundations/Anstalten and VASPs under the bespoke Blockchain Act (TVTG).
Sanctions is not yet covered for this jurisdiction in this report.
Liechtenstein's Register of Beneficial Owners of Legal Entities (VwbP) was breached over the night of 29-30 July 2026, with attackers accessing and copying data covering approximately 31,000 legal entities. The government confirmed the breach on 3 August 2026, and the Prime Minister confirmed on 13 August 2026 that the government will rule out paying any ransom, while officials continue to evaluate possible scenarios. This is assessed rather than confirmed on the available Tier-3 reporting, and no Tier-1 government-portal source has yet corroborated either the precise scale or an attribution. The breach is significant less for its immediate operational consequences than for its timing against a register that MONEYVAL's October 2025 follow-up assessment had already flagged for beneficial-ownership completeness gaps: an under-resourced transparency instrument has now also had its underlying data compromised, compounding rather than introducing a weakness.
As an EEA/EFTA state, Liechtenstein's beneficial-ownership architecture sits within the structural frame set by the European Union's AML Package, which — as a durable backdrop against which this cycle's signal should be read — rests on three distinct instruments: the AML Regulation (AMLR, Reg (EU) 2024/1624), which is directly applicable and carries a July 2027 EU/EEA-wide application date; the sixth AML Directive (6AMLD), transposed per Member State rather than directly applicable; and the AMLA Regulation (Reg (EU) 2024/1620), which establishes the Anti-Money Laundering Authority and shifts the supervisory perimeter from purely national authorities toward a hybrid EU-level regime through a mix of direct and indirect AMLA supervision of higher-risk obliged entities. For Liechtenstein specifically, this architecture is not yet locally binding: the AMLA Regulation remains under review by the EEA Joint Committee and is not yet applicable domestically, meaning Liechtenstein's beneficial-ownership regime for now continues to rest on national instruments — principally the Due Diligence Act (SPG) under FMA supervision — pending eventual EEA incorporation of the EU single rulebook.
That national instrument itself moved this cycle: a national AMLA-implementation consultation report was adopted on 3 March 2026, expanding Obliged Entity scope to crowdfunding providers and intermediaries. This is best read as Liechtenstein pre-positioning its domestic obliged-entity population ahead of eventual EU/EEA architecture convergence, rather than as a response to the later breach, given the adoption date precedes the breach by several months. Liechtenstein remains, notwithstanding both developments, on MONEYVAL's favourable regular follow-up-reporting track, a status dating to its 5th-round Mutual Evaluation Report in June 2022 and reaffirmed at the October 2025 follow-up assessment — the same assessment that flagged the completeness gaps the breach has now compounded.
The obligation environment surrounding the register is itself explicit: the EU AMLR's beneficial-ownership register provisions impose record-keeping obligations relevant to the cross-sector population of obliged entities once the regulation takes local effect, and FATF Recommendation 24 on beneficial-ownership transparency is the multilateral benchmark against which both the pre-breach completeness gaps and the breach itself will be read at Liechtenstein's next MONEYVAL assessment cycle. Because the register is public-sector infrastructure rather than a private obliged-entity system, the breach does not itself trigger the reporting-entity obligations that would apply to a bank or a trust and company service provider; it instead exposes the government as controller of a transparency asset that the private compliance system as a whole depends on for CDD/EDD purposes across the financial centre.
The analytical tension this cycle is between a jurisdiction that continues to earn a favourable multilateral evaluation track record and a transparency register that has just suffered a material compromise of the underlying data MONEYVAL's own assessors had already found incomplete. Both facts are true simultaneously, and the architecture-over-incident framing this monitor applies means the EEA incorporation lag — not the breach alone — is the more durable structural fact to track: whenever AMLR/AMLA incorporation for Liechtenstein does proceed, it will replace the national SPG-based regime with a directly-applicable EU framework carrying its own beneficial-ownership provisions.
The nearest-term question is whether the breach produces a confirmed attribution or a revised scope estimate; the current approximately-31,000-entity figure rests on Tier-3 sourcing only, and a Tier-1 confirmation would materially change the confidence with which this development can be assessed. The more durable item to track is the AMLA Regulation's EEA Joint Committee incorporation timeline for Liechtenstein — the point at which the national SPG-based regime begins yielding to the directly-applicable AMLR — expected around 2027 on current signals but not yet finalised. Whether the 3 March 2026 Obliged Entity expansion to crowdfunding providers proves to be the first of several domestic pre-positioning steps ahead of that incorporation, or a standalone measure, remains to be seen. A further open question is whether the breach prompts an accelerated domestic response ahead of the AMLA/AMLR incorporation timeline, or whether Liechtenstein treats the incident as a discrete operational failure to be remediated without structural reform; either path is consistent with the facts available this cycle.
Enabler Jurisdictions is not yet covered for this jurisdiction in this report.
Conflict Finance is not yet covered for this jurisdiction in this report.
Liechtenstein's twin-track crypto regulatory architecture is approaching its most consequential near-term deadline this cycle. TVTG-registered token and trustworthy-technology service providers that were active before 30 December 2024 must file a complete MiCAR CASP application to continue operating past a transitional grandfathering cut-off, with policy discussion pointing to 30 June or 1 July 2026 as the operative date. This is a Liechtenstein-specific compliance event rather than a purely EU-level one: it determines whether entities that built their compliance posture around the national TVTG framework can continue operating without interruption, or whether they face a supervisory gap if MiCAR authorisation is not secured in time. The FMA sits at the centre of this transition, and the underlying EEA MiCA Implementation Act (EWR-MiCA-DG) — in force since 1 February 2025 — is the Tier-1-confirmed legal basis that gives MiCAR direct effect domestically, even though the specific 30 June 2026 cut-off date itself remains Tier-3-sourced pending firmer confirmation.
Layered onto this licensing-continuity transition is a tax-transparency dimension: the OECD's Crypto-Asset Reporting Framework (CARF) is moving toward first reporting deadlines in 2026, adding new cross-border reporting obligations on top of the AML/CFT supervision the FMA already applies to its CASP population. For firms navigating the TVTG-to-MiCAR transition, this means the compliance burden is not resolved once MiCAR authorisation is secured; a second, tax-transparency-oriented reporting obligation arrives on a similar timeline, compounding rather than replacing the existing AML/CFT and licensing-continuity workstreams. This layering is illustrative of a broader pattern this monitor tracks across enabler and innovation-forward jurisdictions: tax-transparency instruments increasingly ride on the same reporting infrastructure built for AML/CFT purposes, meaning a CASP's investment in one compliance capability increasingly serves double duty.
From a financial-integrity lens, the significance of the MiCAR transition is where it repositions AML/CFT supervision of Liechtenstein's crypto-asset population: entities currently supervised on a national TVTG basis will, once transitioned, sit within the MiCAR/AMLR-aligned supervisory architecture that is itself converging with the broader EU AML Package described elsewhere in this cycle's Liechtenstein coverage. This convergence matters for typology exposure because it changes which rulebook — national or EU-harmonised — governs customer due diligence, beneficial-ownership verification, and suspicious-transaction reporting for VASP-type counterparties operating from or through Liechtenstein. A firm that successfully secures MiCAR CASP status inherits obligations under the EU's crypto-specific AML framework in addition to Liechtenstein's existing FMA-supervised AML/CFT regime; a firm that fails to transition in time faces a more immediate question of continued lawful operation.
The dual-track period itself carries transitional typology risk worth flagging even absent a confirmed incident: during any window where a service provider's authorisation status is ambiguous — no longer clearly covered by TVTG registration but not yet holding a MiCAR CASP licence — the assurance available to counterparties about that provider's AML/CFT status is weaker than in a steady-state regime. This is a structural observation about the transition mechanism itself, not a claim that any specific provider has exploited it, and no evidence of such exploitation has been identified this cycle. No sanctions-nexus or dark-fleet-adjacent crypto development specific to Liechtenstein was identified this cycle; the material signal here is architectural rather than incident-driven.
The near-term marker to watch is confirmation of the exact MiCAR grandfathering cut-off date for TVTG-registered providers: current sourcing points to 30 June or 1 July 2026 but rests on Tier-3 legal-commentary coverage rather than a Tier-1 FMA or legislative confirmation of the precise date. Once that date passes, the next question is how many TVTG-registered providers successfully transitioned versus how many face a supervisory gap. Separately, the OECD CARF's 2026 first-reporting-deadline timeline should be watched for Liechtenstein-specific implementation guidance, since the current signal is a general OECD-level timeline rather than an FMA-confirmed domestic reporting calendar. A further outlook item is whether Liechtenstein's FMA issues consolidated guidance bridging the TVTG and MiCAR regimes for providers mid-transition; no such guidance has been identified in this cycle's sourcing, and its absence is itself worth tracking as a gap rather than a confirmed non-event.
Compliance Technology & Active Defence is not yet covered for this jurisdiction in this report.
Liechtenstein's standing AML/CTF regime centres on the Due Diligence Act (SPG), supervised by the Financial Market Authority (FMA) with the Financial Intelligence Unit (FIU) as the designated reporting entity. This structure has not changed this cycle, but two developments move the regime materially: a national AMLA-implementation consultation report, adopted 3 March 2026, expands Obliged Entity scope to crowdfunding providers and intermediaries; and Liechtenstein's Register of Beneficial Owners — infrastructure the AML/CTF regime depends on for customer due diligence and enhanced due diligence purposes — was breached over 29-30 July 2026, exposing data on approximately 31,000 legal entities.
Liechtenstein remains on MONEYVAL's favourable regular follow-up-reporting track, a status established at its 5th-round Mutual Evaluation Report in June 2022 and reaffirmed at an October 2025 follow-up assessment. That same October 2025 follow-up, however, had already flagged completeness gaps in the beneficial-ownership register now compromised by the breach, meaning the jurisdiction's next MONEYVAL interaction will have to account for both a positive trajectory on its formal evaluation track and an unresolved data-integrity event touching the same registry MONEYVAL had already scrutinised.
Structurally, Liechtenstein's AML/CTF regime sits inside the broader EU AML Package architecture without yet being directly governed by it. That architecture rests on three distinct instruments: the AML Regulation (AMLR, Reg (EU) 2024/1624), directly applicable across the EU with a July 2027 EU/EEA-wide application date; the sixth AML Directive (6AMLD), transposed at Member State level; and the AMLA Regulation (Reg (EU) 2024/1620), establishing the Anti-Money Laundering Authority and shifting supervision from purely national regulators toward a hybrid EU-level model combining direct and indirect AMLA oversight of higher-risk obliged entities. For Liechtenstein as an EEA/EFTA state, this framework requires incorporation via the EEA Joint Committee before it becomes locally binding, and that incorporation has not yet occurred: the AMLA Regulation remains under Joint Committee review, leaving the SPG as the operative domestic instrument for the time being. The 3 March 2026 consultation report is best read as Liechtenstein positioning its domestic Obliged Entity population ahead of that eventual convergence.
The crowdfunding-sector expansion is notable within the three-pillar balance this monitor applies: it is an AML-oriented perimeter expansion — bringing a previously less-supervised sector under SPG obligations — rather than a CTF- or CPF-specific measure, and no CTF- or CPF-specific Liechtenstein development was identified this cycle. This absence is worth surfacing explicitly rather than passing over silently, consistent with this monitor's correction for AML's tendency to dominate reported volume relative to CTF/CPF findings.
The obligation architecture underpinning this regime spans a cross-sector population of obliged entities rather than a single supervised industry, consistent with the FMA's role as an integrated financial supervisor. FATF Recommendation 24, on beneficial-ownership transparency, and Recommendation 15, on new technologies including virtual assets, are the two multilateral benchmarks most directly engaged by this cycle's developments — R.24 through the beneficial-ownership register breach and its interaction with the pre-existing completeness gaps, and R.15 through the crypto-sector obligations layered onto the same SPG/FMA supervisory structure as the TVTG-to-MiCAR transition proceeds. Both recommendations sit within the same MONEYVAL evaluation framework under which Liechtenstein currently holds its favourable follow-up status, meaning any material deterioration on either front carries some risk to that standing even though no formal downgrade signal has been identified this cycle.
The most consequential open question for the AML/CTF regime is the timeline for AMLA/AMLR incorporation into the EEA Agreement for Liechtenstein, currently pointing toward 2027 on available signals but not finalised; once incorporated, large parts of the SPG-based supervisory model will be displaced by the directly-applicable EU rulebook. In the nearer term, whether the Register of Beneficial Owners breach prompts a formal supervisory or remedial response from Liechtenstein authorities, beyond the government's confirmed refusal to pay any ransom, remains unresolved. Whether the crowdfunding-sector Obliged Entity expansion proves to be an isolated adjustment or the first of a series of domestic scope expansions ahead of AMLA convergence is also worth tracking, as is whether regulators address the breach and the TVTG/MiCAR transition through a single coordinated communication or separate, sector-specific channels.
The breach touches infrastructure MLROs rely on for CDD/EDD verification of Liechtenstein-linked entities; combined with the SPG Obliged Entity expansion to crowdfunding providers, the population and data sources relevant to SAR-adjacent monitoring have both shifted this cycle.
Firms newly captured by this expansion face SPG-based due diligence and reporting obligations ahead of eventual AMLA/AMLR convergence, requiring a control-framework gap assessment against the new scope.
Legal teams advising Liechtenstein-exposed entities should track the incorporation timeline as the point at which the operative legal basis for AML supervision shifts from national to directly-applicable EU law.
The breach is a reputational exposure for institutions relying on Liechtenstein's transparency infrastructure, occurring against an otherwise favourable MONEYVAL evaluation trajectory that the board should not assume is unaffected.
Technology and platform teams supporting Liechtenstein-licensed crypto-asset infrastructure should confirm MiCAR CASP application status ahead of the cut-off to avoid a supervisory or operational gap.
Both developments are structural rather than incident-isolated, and risk functions should treat them as compounding rather than independent exposures given they touch overlapping supervisory and data-transparency infrastructure.
Operational teams should confirm whether existing screening and CDD workflows extend to the newly captured sector ahead of the FMA's specification of exact scope and modalities.
Audit functions should note the coexistence of a positive multilateral evaluation trajectory with an unresolved data-integrity event on the same registry MONEYVAL had already flagged, as this may inform future audit-scope decisions on beneficial-ownership evidence reliability.
Liechtenstein's Register of Beneficial Owners was breached, compounding pre-existing MONEYVAL-flagged completeness gaps in the same registry.
Liechtenstein's Obliged Entity scope has been expanded to crowdfunding providers and intermediaries via a March 2026 consultation report.
The AMLA Regulation remains pending EEA Joint Committee incorporation for Liechtenstein, with the AMLR Single Rulebook set to apply EU/EEA-wide from July 2027.
A confirmed personal-data and beneficial-ownership breach at a Liechtenstein government registry raises reputational and financial-centre-adjacency risk.
TVTG-registered virtual-asset providers face a MiCAR transitional cut-off around 30 June/1 July 2026.
The beneficial-ownership breach and the approaching MiCAR/TVTG transition are two concurrent architecture-level risk events for Liechtenstein this cycle.
Onboarding and screening processes for crowdfunding providers and intermediaries newly captured as Liechtenstein Obliged Entities may require adjustment.
Liechtenstein remains on MONEYVAL's favourable regular follow-up-reporting track despite the beneficial-ownership breach.
Illustrative scenario for analytical orientation only: as the AMLA Regulation moves from EEA Joint Committee review toward eventual incorporation, and the directly-applicable AMLR Single Rulebook approaches its July 2027 EU/EEA-wide application date, national supervisory models such as Liechtenstein's SPG-based regime could see a phased displacement of core beneficial-ownership, CDD, and reporting-entity provisions by a directly-applicable EU framework. In such a scenario, cross-border obliged entities operating from smaller EEA/EFTA centres might face a period of dual-track compliance planning analogous to the TVTG-to-MiCAR transition observed in the crypto-asset space, with evasion actors potentially probing the seam between national and EU-level supervisory authority during the changeover window. This is illustrative orientation only, not a prediction of how or when incorporation will occur.
Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.
| Tracker | Status | Note |
|---|---|---|
| T1 · Russian Sanctions-Evasion Architecture | no_change | |
| T2 · EU AML Package / AMLA | watch | AMLD6's beneficial-ownership-register transposition deadline (10 July 2026) passed shortly before LI's BO-register breach, surfacing an implementation/security gap. |
| T3 · FATF Grey List | no_change | LI is not grey-listed; MONEYVAL 5th-round follow-up regime continues. |
| T4 · Beneficial-Ownership Register Status | material_change | LI's national BO register (VwbPG, ~31,000 entity records) was breached and exfiltrated 30 July 2026, confirmed 3 August 2026. |
| T5 · Crypto & Digital-Asset Integrity | no_change | |
| T6 · Sanctions Regime Divergence | no_change |