Data breach in Liechtenstein: How data masking can render stolen data harmless!
The recent cyberattack on a particularly sensitive register in Liechtenstein shows that even comprehensive security measures cannot prevent data theft with absolute certainty. However, data masking can ensure that stolen information remains largely worthless to attackers.
What happened in the Liechtenstein data breach? During the night of 29 to 30 July 2026, unknown perpetrators gained access to Liechtenstein’s ‘Register of Beneficial Owners’. According to the government, data relating to around 31,000 companies, foundations and trusts was copied. The register contains information about the individuals behind these organisations. This includes, amongst other things:
As far as is currently known, account balances, assets, turnover or dividends were not included in the compromised register. Nevertheless, the personal data stolen is sensitive. It could, for example, be used for targeted phishing, identity theft, attempts at blackmail or the creation of detailed personal profiles.
Why traditional IT security alone is not enough: firewalls, access controls, encryption and intrusion detection are indispensable. However, the Liechtenstein case makes it clear that even protected systems can be compromised. As soon as attackers misuse a legitimate or newly created user account, they may be able to access data that is displayed in plain text within the system.
Data protection should therefore not focus solely on securing the systems. The stored and processed data itself must also be protected.
How does data masking make a data breach less dangerous?
Data masking involves replacing personal or confidential information with values that appear realistic but are unusable. Names, dates of birth, addresses or identification numbers are retained in the required format but can no longer be easily linked to a real person.
Depending on the application, different protection methods can be used:
If such data is stolen, attackers will, for example, not obtain the real name and actual date of birth, but rather protected substitute values. Whilst this does not prevent the data breach itself, it significantly reduces its potential consequences.
How does IRI DarkShield support data masking?
IRI DarkShield detects, classifies and masks personal data in unstructured and semi-structured data sources. These include, for example, PDF and Office documents, JSON, XML and Parquet files, log data, images and various NoSQL databases.
DarkShield can automatically scan large data sets for sensitive information. Identified data can then be pseudonymised, encrypted, redacted or otherwise masked according to standardised rules. This is particularly important because personal information is often not stored solely in a central register; it is frequently also found in export files, backups, documents, archives, cloud storage and analytics environments.
For structured data in relational databases, IRI FieldShield complements these functions. Via the IRI Voracity platform, organisations can integrate structured, semi-structured and unstructured data into a unified strategy for data management and data protection.
Does production data need to be fully masked?
A register of data subjects must be able to display the actual information to authorised bodies. Complete masking of all production data would therefore not be practicable.
This makes it all the more important to restrict plain-text access to the absolute minimum. Masked or pseudonymised data should be used in particular for the following areas:
In addition, role-based access controls, consistent data minimisation and the separate storage of identification information can further reduce the risk.
Conclusion: Protect not just the system, but the data too!
The cyberattack in Liechtenstein demonstrates that data security requires more than simply defending against unauthorised access. Companies and public authorities must assume that individual security barriers can be breached.
Data masking using solutions such as IRI DarkShield and IRI FieldShield therefore targets the sensitive information itself. Whilst this does not necessarily prevent a data breach, it can render the stolen data largely unusable to attackers. As a result, successful access to a system does not automatically lead to a catastrophic data protection incident.
Efficiency meets experience: For more than four decades, our software solutions have been supporting companies in data management and data protection – technologically leading, reliable in productive use and applicable across all industries.
In use since 1978: Numerous well-known companies, service providers, financial institutions and state and federal authorities are among our long-standing customers.
Maximum compatibility: Our software supports both classic mainframe platforms (Fujitsu BS2000/OSD, IBM z/OS, z/VSE, z/Linux) and modern open system environments such as Linux, UNIX derivatives and Windows.