DistantNews
Support us
Professionals or amateurs? Liechtenstein struggles to explain cyberattack and possible security failures
๐Ÿ‡ซ๐Ÿ‡ฎ Finland /Technology

Professionals or amateurs? Liechtenstein struggles to explain cyberattack and possible security failures

From Helsingin Sanomat · () Finnish

Translated from Finnish, summarized and contextualized by DistantNews.

At a glance

News Sources not specified Under investigation
  • Liechtenstein is investigating a cyberattack that led to the leak of sensitive data on foundation ownership.
  • The attack has raised questions about the security standards and potential oversights within the country's IT department.
  • While investigators have found traces of the attackers, the technical sophistication of the operation remains unclear, with some experts suggesting a known vulnerability was exploited.

Liechtenstein is grappling with the aftermath of a significant cyberattack that resulted in the leakage of sensitive data concerning the beneficial owners of foundations and other legal entities. The incident has thrust the small principality and its IT department into the international spotlight, prompting urgent investigations into the perpetrators and potential security lapses.

Fabian Schmid, head of the Office for Information Technology, stated that "the attackers are still unknown." He confirmed that "the attackers systematically searched the system until they found a weakness in the application and obtained the desired data." However, the exact technical sophistication of the attack remains a subject of scrutiny.

Klar ist, dass die Angreifer im System systematisch gesucht haben, bis sie eine Schwรคche in der Applikation fanden und an die gewรผnschten Daten kamen.

โ€” Fabian SchmidHead of the Office for Information Technology, describing the cyberattackers' methods.

Information released by Liechtenstein so far has led cybersecurity experts to question whether adequate security standards were followed. Stefan Rothenbรผhler, a cybersecurity expert at Infoguard, suggested that a "classic and generally known type of security vulnerability" might have been exploited. This type of flaw, he explained, could allow a logged-in user with technical knowledge to access data beyond their own entries.

Schmid declined to provide specific details due to the ongoing investigation but acknowledged that "the possibility of accessing certain data arose from a faulty logic in how the application checked permissions." He characterized this as a security vulnerability but differentiated it from a typical software flaw. The application used for the registry was developed and is maintained by an external company, which Schmid indicated is also responsible for its security.

Die Mรถglichkeit, auf bestimmte Daten zuzugreifen, ergab sich aus einer fehlerhaften Logik, wie die Applikation Berechtigungen รผberprรผfte. Dies stelle eine Sicherheitslรผcke dar, unterscheide sich jedoch von einer klassischen Software-Schwachstelle.

โ€” Fabian SchmidHead of the Office for Information Technology, explaining the nature of the security vulnerability.
DistantNews Editorial

Originally published by Helsingin Sanomat in Finnish. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.