Chain IQ breach spilled contact data on more than 100,000 UBS employees
- Organization
- Chain IQ
- Exploit
- Hacking
- Industry
- Business Services
Chain IQ, a procurement services provider based in Zug, Switzerland, was compromised in June 2025 in an attack the company said also hit 19 other organizations. The extortion group World Leaks, a rebrand of Hunters International, listed Chain IQ on its leak site and claimed to have taken roughly 910 GB of data amounting to more than 1.9 million files.
The most widely reported consequence fell on UBS. Records for the bank's staff appeared on the dark web, including names, business email addresses, landline and in some cases mobile telephone numbers, job titles, languages spoken and office floor locations. Reporting on the scale differed: SecurityWeek cited local media putting the figure above 100,000 employees, while Infosecurity Magazine reported around 130,000. A direct number for UBS chief executive Sergio Ermotti was among the exposed entries.
UBS said no client data had been affected and that it took swift action to avoid any impact on its operations. Pictet, another Swiss bank on Chain IQ's client list, said the material taken related to invoices from suppliers such as technology providers and external consultants and included no client information. Retailer Manor and construction group Implenia were also reported among those caught up in the incident.
Chain IQ described the intrusion as an attack on a scale never before seen globally, said it had contained the incident within roughly nine hours of detection, and confirmed that data belonging to some customers had been exfiltrated, specifically employee business contact details and internal telephone numbers. It did not discuss any ransom demand.