Company Details
ubs
118,265
2,039,826
52
ubs.com
362
UBS_2194882
Completed


UBS Company CyberSecurity Posture
ubs.comFrom gaining new experiences in different roles to acquiring fresh knowledge and skills – at UBS we believe that you should never stop growing and learning because life never stops teaching. We know that it's our people – with their unique backgrounds, skills, experience levels and interests – who drive our ongoing success. Ready to be part of #teamUBS and make an impact? Find out more at ubs.com/careers. UBS works with individuals, families, institutions, and corporations around the world to help answer some of life's questions – whether through award winning wealth management advisory, investment banking and asset management expertise, or private and corporate banking services in Switzerland*. In June 2023, Credit Suisse became a UBS Group company. With our large and diverse team operating internationally, we have a presence in all major financial centers in more than 50 countries. Although we all come from different backgrounds and specializations, two things unite us: the conviction that we’re stronger together, and the will and curiosity to constantly innovate. That’s the key to us unlocking our full potential (and what we look for in everyone who joins us). It’s also why we’re regularly recognized as an attractive employer.* * Our awards https://www.ubs.com/awards Social Media Legal Terms: http://www.ubs.com/social-legal
Company Details
ubs
118,265
2,039,826
52
ubs.com
362
UBS_2194882
Completed
Between 750 and 799

UBS Global Score (TPRM)XXXX

Description: Global banking giant UBS has suffered a data breach following a cyber-attack on a third-party supplier. Information about 130,000 UBS employees, including their business contact details, job roles, locations, and floor information, was published on the dark web by a ransomware group called World Leaks. The breach did not impact customer data or operations, but the direct phone number of UBS CEO Sergio Ermotti was included in the published data.


No incidents recorded for UBS in 2026.
No incidents recorded for UBS in 2026.
No incidents recorded for UBS in 2026.
UBS cyber incidents detection timeline including parent company and subsidiaries

From gaining new experiences in different roles to acquiring fresh knowledge and skills – at UBS we believe that you should never stop growing and learning because life never stops teaching. We know that it's our people – with their unique backgrounds, skills, experience levels and interests – who drive our ongoing success. Ready to be part of #teamUBS and make an impact? Find out more at ubs.com/careers. UBS works with individuals, families, institutions, and corporations around the world to help answer some of life's questions – whether through award winning wealth management advisory, investment banking and asset management expertise, or private and corporate banking services in Switzerland*. In June 2023, Credit Suisse became a UBS Group company. With our large and diverse team operating internationally, we have a presence in all major financial centers in more than 50 countries. Although we all come from different backgrounds and specializations, two things unite us: the conviction that we’re stronger together, and the will and curiosity to constantly innovate. That’s the key to us unlocking our full potential (and what we look for in everyone who joins us). It’s also why we’re regularly recognized as an attractive employer.* * Our awards https://www.ubs.com/awards Social Media Legal Terms: http://www.ubs.com/social-legal


For over 180 years, we’ve helped turn your biggest dreams into milestones that last a lifetime. As a mutual company we hold ourselves to the highest standards of transparency, objectivity, and integrity. We’re committed to improving local communities through a culture of giving and volunteerism, sup

Angel One Limited is a Fintech company providing broking services, margin trading facility, research services, depository services, investment education and distribution of third-party financial products to its clients, on a mission to become the No. 1 fintech organization in India. With about 32 mi

A XP Inc. é uma das maiores instituições financeiras independente do Brasil, dona das marcas XP, Rico, Clear, XP Educação, InfoMoney, entre outras. Com mais de 4,6 milhões de clientes ativos e um valor superior a R$ 1,3 trilhão de ativos sob custódia, há 24 anos vem transformando o mercado financeir

Franklin Resources, Inc. [NYSE:BEN] is a global investment management organization with subsidiaries operating as Franklin Templeton (www.franklinresources.com). The products, services, information and materials referenced in this site may not be available to residents in certain jurisdictions. Co
We aspire to be the world’s most exceptional financial institution, united by our shared values of partnership, client service, integrity, and excellence. Operating at the center of capital markets, we act as one firm, mobilizing our people, capital, and ideas to deliver superior results across ou

As a brand with a legacy of over 160 years in Africa, we have a deep understanding and belief in the boundless opportunities that this continent presents. Our vision extends beyond mere geography; it encompasses a profound recognition of the potential for growth that resonates within our people, cus

Morgan Stanley (NYSE: MS) is a leading global financial services firm providing a wide range of investment banking, securities, wealth management and investment management services. With offices in 42 countries, our firm's employees serve clients worldwide including corporations, governments, instit

SMBC Group is a top-tier global financial group. Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance. The Group has more than 150 offices and 120,000 employees worldwid

J.P. Morgan is a leader in financial services, offering solutions to clients in more than 100 countries with one of the most comprehensive global product platforms available. We have been helping our clients to do business and manage their wealth for more than 200 years. Our business has been built
.png)
Quantum computing is an industry with 'extraordinary potential,' according to investment bank UBS, which has highlighted a select group of...
Palo Alto Networks Inc. (NASDAQ:PANW) is among the best debt-free stocks to buy now. According to a January 13 report by The Fly, UBS cut...
UBS has pushed back against Swiss government proposals to tighten banking capital rules introduced in the wake of the 2023 collapse of...
UBS Group recently released its 2026 outlook report on the cybersecurity sector, maintaining a positive outlook for the industry.
MyFO has shared an update. The company highlighted key findings from UBS's Q1 2026 Family Office Quarterly report, emphasizing gaps in...
Why is cybersecurity considered a long-term megatrend? Cybersecurity is growing worldwide and attracting high levels of investment. The drivers...
UBS has unveiled a curated list of 30 companies it believes are best positioned to thrive over the coming decade. See the list here.
Ameriprise reported gaining 90 advisors during the third quarter while UBS stated in its earnings that advisor headcount dropped to 5779 in...
China's Cybersecurity Law: China's proposed AI law aims to boost research, improve ethics, strengthen risk checks and enhance safety...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of UBS is http://www.ubs.com/about.
According to Rankiteo, UBS’s AI-generated cybersecurity score is 766, reflecting their Fair security posture.
According to Rankiteo, UBS currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, UBS has not been affected by any supply chain cyber incidents, and no incident IDs are currently listed for the organization.
According to Rankiteo, UBS is not certified under SOC 2 Type 1.
According to Rankiteo, UBS does not hold a SOC 2 Type 2 certification.
According to Rankiteo, UBS is not listed as GDPR compliant.
According to Rankiteo, UBS does not currently maintain PCI DSS compliance.
According to Rankiteo, UBS is not compliant with HIPAA regulations.
According to Rankiteo,UBS is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
UBS operates primarily in the Financial Services industry.
UBS employs approximately 118,265 people worldwide.
UBS presently has no subsidiaries across any sectors.
UBS’s official LinkedIn profile has approximately 2,039,826 followers.
UBS is classified under the NAICS code 52, which corresponds to Finance and Insurance.
No, UBS does not have a profile on Crunchbase.
Yes, UBS maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/ubs.
As of January 25, 2026, Rankiteo reports that UBS has experienced 1 cybersecurity incidents.
UBS has an estimated 30,839 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Ransomware.
Detection and Response: The company detects and responds to cybersecurity incidents through an containment measures with strengthened security of relevant systems..
Title: UBS Data Breach via Third-Party Supplier
Description: Global banking giant UBS has suffered a data breach following a cyber-attack on a third-party supplier, Chain IQ. Information about 130,000 UBS employees was published on the dark web by a ransomware group called World Leaks. The data included business contact details, job roles, and locations. UBS confirmed that no client data was affected.
Date Detected: 2023-06-12
Date Publicly Disclosed: 2023-06-12
Type: Data Breach
Attack Vector: Third-party supplier compromise
Threat Actor: World Leaks (Hunters International)
Motivation: Data exfiltration and potential ransom demand
Common Attack Types: The most common types of attacks the company has faced is Ransomware.

Data Compromised: Business contact details, Job roles, Locations
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Business Contact Details, Job Roles, Locations and .

Entity Name: UBS
Entity Type: Bank
Industry: Financial Services
Location: Switzerland

Entity Name: Pictet
Entity Type: Bank
Industry: Financial Services
Location: Switzerland

Entity Name: Chain IQ
Entity Type: Procurement Service Provider
Industry: Services
Location: Switzerland

Containment Measures: Strengthened security of relevant systems

Type of Data Compromised: Business contact details, Job roles, Locations
Number of Records Exposed: 130000
Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by strengthened security of relevant systems and .

Data Exfiltration: True

Source: Infosecurity
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Infosecurity.

Investigation Status: Ongoing
Last Attacking Group: The attacking group in the last incident was an World Leaks (Hunters International).
Most Recent Incident Detected: The most recent incident detected was on 2023-06-12.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2023-06-12.
Most Significant Data Compromised: The most significant data compromised in an incident were Business contact details, Job roles, Locations and .
Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident was Strengthened security of relevant systems.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Business contact details, Job roles and Locations.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 130.0.
Most Recent Source: The most recent source of information about an incident is Infosecurity.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing.
.png)
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the processBackgroundAction() function in all versions up to, and including, 10.0.04. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify global map engine settings.
The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘options’ parameter in all versions up to, and including, 4.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. NOTE: Successful exploitation of this vulnerability requires that the PDFCrowd API key is blank (also known as "demo mode", which is the default configuration when the plugin is installed) or known.
The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the action_import_module() function in all versions up to, and including, 7.8.9.2. This makes it possible for authenticated attackers, with a lower-privileged role (e.g., Subscriber-level access and above), to upload arbitrary files on the affected site's server which may make remote code execution possible. Successful exploitation requires an admin to grant Hustle module permissions (or module edit access) to the low-privileged user so they can access the Hustle admin page and obtain the required nonce.
The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_public_action AJAX handler. This makes it possible for unauthenticated attackers to extract email addresses for users with Directory Kit-specific user roles.
The Meta-box GalleryMeta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.