Cyber Incident Victim: UBS
Date:
Jun 2025
Location:
Switzerland
Summary
A ransomware attack on the procurement service provider Chain IQ resulted in the theft of roughly 1.9 million files totalling about 910 gigabytes, including personal data of around 130,000 UBS employees and the internal phone number of CEO Sergio Ermotti, which appeared on the darknet. The breach, attributed to the Worldleaks group, also affected nineteen other organizations and exposed over 230,000 invoice entries from the Geneva‑based bank Pictet, though Chain IQ stated that no customer information was compromised and that it has notified authorities and alerted affected business clients.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
The incident became public last week when the ransomware group Worldleaks announced that it had compromised Chain IQ, a procurement service provider that originated as a spin‑off of UBS and is headquartered in Baar. According to the report from Le Temps cited by Blick, the attackers exfiltrated more than 1.9 million files amounting to roughly 910 gigabytes of data from Chain IQ’s systems. The breach also extended to nineteen additional companies that were compromised in the same campaign. Chain IQ confirmed that the attack was carried out by the Worldleaks ransomware group.

Among the stolen data were personal details of approximately 130,000 UBS employees, including the internal telephone number of CEO Sergio Ermotti, which appeared in the darknet although Chain IQ noted that the number is not reachable from outside the organization. The leaked material also contained a separate file with over 230,000 invoice positions belonging to the Geneva‑based bank Pictet. The article explicitly states that customer information was not part of the disclosed data. In addition to UBS, Chain IQ’s client list in Switzerland includes Manor and Implenia, though the article does not specify whether their data was affected.
Following the discovery, Chain IQ informed the relevant authorities and alerted its affected business customers about the breach. The company clarified that while the internal phone number of Sergio Ermotti was visible in the darknet, it cannot be dialed from external lines. Chain IQ, founded in 2013 as a UBS spin‑off, operates offices across Europe, Asia and the United States and continues to cooperate with investigators regarding the Worldleaks ransomware attack.
