Skip to main content
Back to overview
Medium

Pictet Employee Data Compromised in Chain IQ Breach

Chain IQ data breach affects major banks and companies in Switzerland Chain IQ, a large company dedicated to procurement and indirect purchasing services, was the target of a cyber-attack affecting the data of 19 other…

Key points

  • Impacted by third-party Chain IQ data breach.
  • Employee business contact details and internal phone numbers compromised.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Malware, Hacking, Error activity

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Jun 11, 2025
Updated
Jul 22, 2026
Confidence
Medium
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Hacking, Error activity

The feed marks multiple actor roles. Treat this as a review signal rather than a final attribution.

  • Source type: possible insider or internal misuse
  • Source type: supplier or third-party involvement

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

PictetData DisclosureSwitzerland Chain IQAmong theUBSPictetManorImpleniaKPMGMizuho. The

Quick context

Questions about this signal

What happened in this signal?

Chain IQ data breach affects major banks and companies in Switzerland Chain IQ, a large company dedicated to procurement and indirect purchasing services, was the target of a cyber-attack affecting the data of 19 other companies. Among the affected companies, the media highlighted names such as UBS, Pictet, Manor, Implenia, KPMG or Mizuho. The attack was claimed on June 11, 2025 by the ransomware group Worldleaks, which published the breach of Chain IQ's systems on its Tor-based leak website. It announced the theft of about 910 GB of data and more than 1.9 million files. The stolen information is related to the purchases of some customers who contract Chain IQ's services. The company itself claimed that the attackers managed to extract data containing business contact details of employees of selected customers, including the employees' phone numbers. Following the release of the data, Chain IQ notified law enforcement authorities and began reviewing all of its systems, strengthening protective measures and cutting off the attackers' access to the affected environment. In fact, it also managed to restore software introduced by the attackers during the attack for further analysis. Chain IQ is working with InfoGuard and Kyndryl to maintain the security of its systems. 17/06/2025 letemps.ch Plus de 100 000 employés d’UBS touchés par un vol massif de données sensibles, affectant aussi Pictet 19/06/2025 securityweek.com Chain IQ, UBS Data Stolen in Ransomware Attack 19/06/2025 chainiq.com Cyber-Attack Chain IQ Group AG 18/06/2025 reuters.com UBS and Pictet report data leak after cyber attack on provider, client data unaffected 18/06/2025 marketscreener.com UBS y Pictet informan de filtración de datos tras ciberataque a proveedor; datos de clientes no afectados Swiss procurement service provider Chain IQ has confirmed falling victim to a cyberattack that led to the theft of customer data. The Zug, Switzerland-based firm says it learned of the incident after a threat actor published data allegedly stolen from its systems on the dark web. “On June 12, 2025, Chain IQ, along with 19 other companies, was the target of a cyberattack that had never before been seen on a global scale. This cyberattack resulted in data theft. Data from some Chain IQ customers was published on the dark web,” the company says in an incident notice . Chain IQ says it immediately activated its response plan and checked all relevant systems, and notified customers, employees, and partner companies, as well as the relevant authorities. “The incident was contained after 8 hours and 45 minutes by revoking the attackers’ access to the affected environment,” the company says. Chain IQ said no bank customer data was compromised in the incident, but confirmed that the attackers exfiltrated “data containing employee business contact details of selected clients”, including client employees’ phone numbers. Advertisement. Scroll to continue reading. According to local media , Swiss financial groups UBS and Pictet, as well as Manor, and real estate and construction services company Implenia were impacted. Responding to a SecurityWeek inquiry, UBS confirmed the impact from the incident, but said that no client data was stolen in the attack. “A cyber-attack at an external supplier has led to information about UBS and several other companies being stolen. No client data has been affected. As soon as UBS became aware of the incident, it took swift and decisive action to avoid any impact on its operations,” UBS said. The attack on Chain IQ was claimed by the ransomware group Worldleaks, which added the company to its Tor-based leak site on June 11, claiming the theft of roughly 910 GB of data, or more than 1.9 million files. “External suppliers have become one of the most readily attacked, compromised, and exploited organizations that we deal with,” Neovera VP Paul Underwood said in an emailed comment. “Although in a statement it was reported that no client data was involved in the cyberattack, it does not mean that the cyberattack does not have value to not only the attacker but to what potentially could happen in the future to these organizations that were affected,” Underwood continued. Related: Krispy Kreme Confirms Data Breach After Ransomware Attack Related: Anubis Ransomware Packs a Wiper to Permanently Delete Files Related: Fog Ransomware Attack Employs Unusual Tools Related: Sensitive Information Stolen in Sensata Ransomware Attack Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Clover Health Investments Discloses Data Breach Zimbra Update Patches Critical Vulnerabilities OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Ernst & Young Data Breach Affects Personal, Financial Information Hugging Face Hacked in Autonomous AI Attack Chrome 150 Update Patches Severe Memory Safety Bugs Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

When was this signal reported?

Shadow Tier lists Jun 11, 2025 as the signal date.

Which organization is connected to this signal?

Pictet is the organization connected to this public signal.

Explore Pictet
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence