Desk live·
ForensicPost
Breaches/Third party/File 25-0613

Chain IQ Breach Exposed 130,000 Employee Records Across 19 Clients

Chain IQ Group was compromised on 12 June 2025, exposing more than 130,000 employee records across at least 19 client organisations including UBS and Pictet. The data described staff, not customers.

Constructed geometry · not a chart of case data
TargetChain IQ Group AG
ActorUnattributed
S. Rosler11 min readConfidence: high2 sources reviewed

Procurement services vendor Chain IQ Group AG was compromised on 12 June 2025. Data belonging to Chain IQ and at least 19 of its client organisations was uploaded to a leak site shortly afterwards, including more than 130,000 employee records — names, email addresses, telephone numbers and workplace location codes — from firms including UBS and Pictet.

This Corpus Is Almost Entirely About Customers

Nearly every file here concerns data about the people an organisation serves. Employee data appears rarely, and when it does it is usually incidental to a larger customer exposure.

That imbalance is not a reflection of reality. It reflects notification law, which is built around consumers and generates the public record this corpus is assembled from. Workforce data is exposed constantly and produces far less signal.

Names Plus Employers Plus Locations Is A Targeting List

Individually these are mundane fields. Together they establish who works for which institution, in what capacity, at which site, with a working contact route.

For an attacker running the social-engineering campaigns this database is full of — 25-0512, 25-0514, 25-0701 — that is the reconnaissance phase completed. Knowing that a named person works at a specific bank, at a specific location, and how to reach them, is precisely what makes a pretext credible.

The corpus therefore has to record this as a supply of input to future incidents rather than as a self-contained event.

Nineteen Clients, One Procurement Platform

Procurement outsourcing consolidates purchasing across organisations to extract volume discounts. It works, and the saving is real.

What follows is that a function nobody considers sensitive — buying things — accumulates the staff directories of every client. It is the concentration structure filed at 25-0814 and 25-0801, in a back-office function that would not appear on any list of critical suppliers.

How we reported this

Compiled from public reporting, listed below. The client count is a reported minimum. We have not reviewed the published data. Corrections: corrections@forensicpost.com.

Sources
  1. June 2025 data breach round-up: major cybersecurity incidentsFindings
  2. Top third-party data breachesFortifyData
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary