UBS Group, Pictet and Implenia said they were among the companies affected by a cyberattack on procurement firm Chain IQ. Here’s the details:
Swiss banks UBS and Pictet said on Wednesday they had suffered a data leak due to a cyber attack on a provider in Switzerland that did not compromise client information, although a report said thousands of UBS workers’ data was affected.
Swiss newspaper Le Temps said that files containing details of tens of thousands of UBS employees were stolen from the Baar-based business service company Chain IQ, whose website lists KPMG and Mizuho among its clients.
A cyber attack at an external supplier has led to information about UBS and several other companies being stolen. No client data has been affected,” UBS said.
“As soon as UBS became aware of the incident, it took swift and decisive action to avoid any impact on its operations.”
The leaked cache also included the number of a direct internal line to UBS CEO Sergio Ermotti, Le Temps reported.
Chain IQ said it and 19 other companies were targeted in the attack, resulting in leaked data being published online on the darknet – a part of the internet not accessible through standard search engines.
Ensar Seker, CISO at SOCRadar had this to say:
“The Chain IQ breach underscores the persistent and growing risk of third-party exposure in today’s interconnected enterprise ecosystem. When suppliers hold sensitive operational or financial data, even in the absence of client PII, they become a highly attractive target for threat actors seeking leverage, intelligence, or access pathways into high-value organizations.
“What’s notable here is that the breach impacted major financial and consulting institutions, which typically maintain rigorous internal security controls. This demonstrates that the weakest link often lies outside the perimeter.
From a threat intelligence perspective, leaks involving executive or employee-level data, especially those of high-profile individuals like UBS’s CEO, increase the likelihood of targeted phishing, social engineering, or even impersonation attempts. Even when no client data is compromised, operational metadata like invoice histories, consultant relationships, or IT supplier engagements can provide adversaries with useful insights for crafting sophisticated campaigns. This is a classic case where traditional third-party risk management needs to mature into continuous fourth-party visibility and active vendor monitoring. Organizations must go beyond one-time assessments and require vendors to maintain threat detection telemetry, incident reporting SLAs, and breach simulation exercises. Additionally, platforms that provide real-time breach alerts on vendors such as DRP and supply chain intelligence solutions are no longer optional but essential to reduce response lag.
“Chain IQ’s breach serves as yet another reminder that “trust, but verify” is not just a saying, it should be embedded into every enterprise’s third-party governance model.”
James McQuiggan, Security Awareness Advocate at KnowBe4 follows with this:
“Trust alone isn’t enough when it comes to third-party risk and cybersecurity. Organizations need to manage third-party risk actively. Don’t rely on a one-time assessment or questionnaire. It’s crucial to consider regularly reviewing vendors’ protection of their data and systems. Keep checking in, especially with vendors that handle sensitive information. When a vendor is compromised, a quick response can be significant.
“Organizations should have a well-documented and repeatable plan for handling a third-party incident or breach. Consider how to isolate the issue, who to contact, and how to communicate with employees and partners. Rate your vendors based on risk levels: one that has strong security programs versus one that does not. Higher risk vendors require additional oversight and tighter security controls.”
You’re only as secure as your suppliers are. Organizations need to start buying into that by acting accordingly when it comes to their security. If a significant amount of organizations did that, supply chain attacks would be greatly reduced.
Related
This entry was posted on June 18, 2025 at 2:06 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
A Number Of Companies Have Been Pwned Via A Supply Chain Attack
UBS Group, Pictet and Implenia said they were among the companies affected by a cyberattack on procurement firm Chain IQ. Here’s the details:
Swiss banks UBS and Pictet said on Wednesday they had suffered a data leak due to a cyber attack on a provider in Switzerland that did not compromise client information, although a report said thousands of UBS workers’ data was affected.
Swiss newspaper Le Temps said that files containing details of tens of thousands of UBS employees were stolen from the Baar-based business service company Chain IQ, whose website lists KPMG and Mizuho among its clients.
A cyber attack at an external supplier has led to information about UBS and several other companies being stolen. No client data has been affected,” UBS said.
“As soon as UBS became aware of the incident, it took swift and decisive action to avoid any impact on its operations.”
The leaked cache also included the number of a direct internal line to UBS CEO Sergio Ermotti, Le Temps reported.
Chain IQ said it and 19 other companies were targeted in the attack, resulting in leaked data being published online on the darknet – a part of the internet not accessible through standard search engines.
Ensar Seker, CISO at SOCRadar had this to say:
“The Chain IQ breach underscores the persistent and growing risk of third-party exposure in today’s interconnected enterprise ecosystem. When suppliers hold sensitive operational or financial data, even in the absence of client PII, they become a highly attractive target for threat actors seeking leverage, intelligence, or access pathways into high-value organizations.
“What’s notable here is that the breach impacted major financial and consulting institutions, which typically maintain rigorous internal security controls. This demonstrates that the weakest link often lies outside the perimeter.
From a threat intelligence perspective, leaks involving executive or employee-level data, especially those of high-profile individuals like UBS’s CEO, increase the likelihood of targeted phishing, social engineering, or even impersonation attempts. Even when no client data is compromised, operational metadata like invoice histories, consultant relationships, or IT supplier engagements can provide adversaries with useful insights for crafting sophisticated campaigns. This is a classic case where traditional third-party risk management needs to mature into continuous fourth-party visibility and active vendor monitoring. Organizations must go beyond one-time assessments and require vendors to maintain threat detection telemetry, incident reporting SLAs, and breach simulation exercises. Additionally, platforms that provide real-time breach alerts on vendors such as DRP and supply chain intelligence solutions are no longer optional but essential to reduce response lag.
“Chain IQ’s breach serves as yet another reminder that “trust, but verify” is not just a saying, it should be embedded into every enterprise’s third-party governance model.”
James McQuiggan, Security Awareness Advocate at KnowBe4 follows with this:
“Trust alone isn’t enough when it comes to third-party risk and cybersecurity. Organizations need to manage third-party risk actively. Don’t rely on a one-time assessment or questionnaire. It’s crucial to consider regularly reviewing vendors’ protection of their data and systems. Keep checking in, especially with vendors that handle sensitive information. When a vendor is compromised, a quick response can be significant.
“Organizations should have a well-documented and repeatable plan for handling a third-party incident or breach. Consider how to isolate the issue, who to contact, and how to communicate with employees and partners. Rate your vendors based on risk levels: one that has strong security programs versus one that does not. Higher risk vendors require additional oversight and tighter security controls.”
You’re only as secure as your suppliers are. Organizations need to start buying into that by acting accordingly when it comes to their security. If a significant amount of organizations did that, supply chain attacks would be greatly reduced.
Share this:
Like this:
Related
This entry was posted on June 18, 2025 at 2:06 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.