Company Details
ubs
118,118
1,880,643
52
ubs.com
362
UBS_2194882
Completed

UBS Company CyberSecurity Posture
ubs.comFrom gaining new experiences in different roles to acquiring fresh knowledge and skills – at UBS we believe that you should never stop growing and learning because life never stops teaching. We know that it's our people – with their unique backgrounds, skills, experience levels and interests – who drive our ongoing success. Ready to be part of #teamUBS and make an impact? Find out more at ubs.com/careers. UBS works with individuals, families, institutions, and corporations around the world to help answer some of life's questions – whether through award winning wealth management advisory, investment banking and asset management expertise, or private and corporate banking services in Switzerland*. In June 2023, Credit Suisse became a UBS Group company. With our large and diverse team operating internationally, we have a presence in all major financial centers in more than 50 countries. Although we all come from different backgrounds and specializations, two things unite us: the conviction that we’re stronger together, and the will and curiosity to constantly innovate. That’s the key to us unlocking our full potential (and what we look for in everyone who joins us). It’s also why we’re regularly recognized as an attractive employer.* * Our awards https://www.ubs.com/awards Social Media Legal Terms: http://www.ubs.com/social-legal
Company Details
ubs
118,118
1,880,643
52
ubs.com
362
UBS_2194882
Completed
Between 750 and 799

UBS Global Score (TPRM)XXXX

Description: Global banking giant UBS has suffered a data breach following a cyber-attack on a third-party supplier. Information about 130,000 UBS employees, including their business contact details, job roles, locations, and floor information, was published on the dark web by a ransomware group called World Leaks. The breach did not impact customer data or operations, but the direct phone number of UBS CEO Sergio Ermotti was included in the published data.


UBS has 21.95% more incidents than the average of same-industry companies with at least one recorded incident.
UBS has 29.87% more incidents than the average of all companies with at least one recorded incident.
UBS reported 1 incidents this year: 0 cyber attacks, 1 ransomware, 0 vulnerabilities, 0 data breaches, compared to industry peers with at least 1 incident.
UBS cyber incidents detection timeline including parent company and subsidiaries

From gaining new experiences in different roles to acquiring fresh knowledge and skills – at UBS we believe that you should never stop growing and learning because life never stops teaching. We know that it's our people – with their unique backgrounds, skills, experience levels and interests – who drive our ongoing success. Ready to be part of #teamUBS and make an impact? Find out more at ubs.com/careers. UBS works with individuals, families, institutions, and corporations around the world to help answer some of life's questions – whether through award winning wealth management advisory, investment banking and asset management expertise, or private and corporate banking services in Switzerland*. In June 2023, Credit Suisse became a UBS Group company. With our large and diverse team operating internationally, we have a presence in all major financial centers in more than 50 countries. Although we all come from different backgrounds and specializations, two things unite us: the conviction that we’re stronger together, and the will and curiosity to constantly innovate. That’s the key to us unlocking our full potential (and what we look for in everyone who joins us). It’s also why we’re regularly recognized as an attractive employer.* * Our awards https://www.ubs.com/awards Social Media Legal Terms: http://www.ubs.com/social-legal

The Allianz Group is one of the world's leading insurers and asset managers with more than 100 million private and corporate customers in nearly 70 countries. We are proud to be the Worldwide Insurance Partner of the Olympic & Paralympic Movements from 2021 until 2032 and to be recognized as one of

We are here. So you can stay ahead. For nearly two hundred years we have acquired and shared knowledge, developed global networks and adapted to modern everyday life. To us, it is important to combine profitability with responsibility. DNB is Norway's largest financial services group and one of t

Shriram Finance is the country’s biggest retail NBFC offering credit solutions for commercial vehicles, two-wheeler loans, car loans, home loans, gold loans, personal and small business loans. We are part of the 50-year-old Shriram Group, a financial conglomerate that has emerged as a trusted partne
SBI Card was launched in 1998 with the State Bank of India, India's largest bank, as the majority stakeholder. In March 2020, SBI Card was listed on BSE and NSE. Today, SBI Card is India’s largest pure-play credit card issuer with over 19.5 million cards in force, as of September 2024. Its wide arra

Bloomberg is a global leader in business and financial information, delivering trusted data, news, and insights that bring transparency and efficiency, and fairness to markets. We help connect influential communities across the global financial ecosystem via reliable technology solutions that enable

Founded in the year 2000, the Indiabulls Group is one of the country’s leading business houses with interest across sectors like financial services, real estate, pharmaceutical and LED. Headquartered in Gurgaon, all the group companies are listed on the Bombay Stock Exchange, and the National Stock

At American Express, we know that with the right backing, people and businesses have the power to progress in incredible ways. Whether we’re supporting our customers’ financial confidence to move ahead, taking commerce to new heights, or encouraging people to explore the world, our colleagues are co

CIMB Group is a leading ASEAN universal bank, one of the largest Asian investment banks and one of the world's largest Islamic banks. We are headquartered in Kuala Lumpur, Malaysia and offer consumer banking, commercial banking, wholesale banking, Islamic banking, and asset management products and

Morgan Stanley (NYSE: MS) is a leading global financial services firm providing a wide range of investment banking, securities, wealth management and investment management services. With offices in 42 countries, our firm's employees serve clients worldwide including corporations, governments, instit
.png)
On December 4, a daring ATM heist at a UBS branch in Gland shook the Swiss banking community, highlighting potential vulnerabilities in...
Dubai/United Arab Emirates – UBS, the leading and truly global wealth manager, today announced the publication of the 11th UBS Billionaire...
Invest in the future of cybersecurity. Seize the opportunity to participate in the growth potential of the international cybersecurity industry.
UBS Global Wealth Management (GWM) Middle East has appointed Borja Martinez-Laredo as Location Head of its newly launched Abu Dhabi office,...
UBS has unveiled a curated list of 30 companies it believes are best positioned to thrive over the coming decade, emphasizing that the next wave of market...
Wall Street's artificial intelligence-driven rally will extend into 2026, UBS Global Research said on Monday, as the brokerage set the S&P...
Cisco Systems (CSCO) was upgraded to Buy from Neutral by UBS due to its critical role in the buildout of artificial intelligence infrastructure.
Investigative body cautions Swiss lender after complaint over its holdings in two US private prisons.
China's Cybersecurity Law: China's proposed AI law aims to boost research, improve ethics, strengthen risk checks and enhance safety...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of UBS is http://www.ubs.com/about.
According to Rankiteo, UBS’s AI-generated cybersecurity score is 759, reflecting their Fair security posture.
According to Rankiteo, UBS currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, UBS is not certified under SOC 2 Type 1.
According to Rankiteo, UBS does not hold a SOC 2 Type 2 certification.
According to Rankiteo, UBS is not listed as GDPR compliant.
According to Rankiteo, UBS does not currently maintain PCI DSS compliance.
According to Rankiteo, UBS is not compliant with HIPAA regulations.
According to Rankiteo,UBS is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
UBS operates primarily in the Financial Services industry.
UBS employs approximately 118,118 people worldwide.
UBS presently has no subsidiaries across any sectors.
UBS’s official LinkedIn profile has approximately 1,880,643 followers.
UBS is classified under the NAICS code 52, which corresponds to Finance and Insurance.
Yes, UBS has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/ubs.
Yes, UBS maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/ubs.
As of December 11, 2025, Rankiteo reports that UBS has experienced 1 cybersecurity incidents.
UBS has an estimated 30,346 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Ransomware.
Detection and Response: The company detects and responds to cybersecurity incidents through an containment measures with strengthened security of relevant systems..
Title: UBS Data Breach via Third-Party Supplier
Description: Global banking giant UBS has suffered a data breach following a cyber-attack on a third-party supplier, Chain IQ. Information about 130,000 UBS employees was published on the dark web by a ransomware group called World Leaks. The data included business contact details, job roles, and locations. UBS confirmed that no client data was affected.
Date Detected: 2023-06-12
Date Publicly Disclosed: 2023-06-12
Type: Data Breach
Attack Vector: Third-party supplier compromise
Threat Actor: World Leaks (Hunters International)
Motivation: Data exfiltration and potential ransom demand
Common Attack Types: The most common types of attacks the company has faced is Ransomware.

Data Compromised: Business contact details, Job roles, Locations
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Business Contact Details, Job Roles, Locations and .

Entity Name: UBS
Entity Type: Bank
Industry: Financial Services
Location: Switzerland

Entity Name: Pictet
Entity Type: Bank
Industry: Financial Services
Location: Switzerland

Entity Name: Chain IQ
Entity Type: Procurement Service Provider
Industry: Services
Location: Switzerland

Containment Measures: Strengthened security of relevant systems

Type of Data Compromised: Business contact details, Job roles, Locations
Number of Records Exposed: 130000
Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by strengthened security of relevant systems and .

Data Exfiltration: True

Source: Infosecurity
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Infosecurity.

Investigation Status: Ongoing
Last Attacking Group: The attacking group in the last incident was an World Leaks (Hunters International).
Most Recent Incident Detected: The most recent incident detected was on 2023-06-12.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2023-06-12.
Most Significant Data Compromised: The most significant data compromised in an incident were Business contact details, Job roles, Locations and .
Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident was Strengthened security of relevant systems.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Job roles, Business contact details and Locations.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 130.0.
Most Recent Source: The most recent source of information about an incident is Infosecurity.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing.
.png)
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone admin password. This issue is fixed in versions 16.0.96 and 17.0.10.
Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent context it becomes a high-risk capability: prompt injection or indirect prompt manipulation can cause execution of destructive queries such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements (subject to DB permissions). Deployments that expose an agent with MySQLWriteTool enabled to untrusted input and/or run the tool with a DB user that has broad privileges are impacted. This issue is fixed in version 2.8.12.
Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SELECT) and a forbidden-keyword list does not block file-writing constructs such as INTO OUTFILE / INTO DUMPFILE. As a result, an attacker who can influence the tool input (e.g., via prompt injection through a public agent endpoint) may write arbitrary files to the DB server if the MySQL/MariaDB account has the FILE privilege and server configuration permits writes to a useful location (e.g., a web-accessible directory). This issue is fixed in version 2.8.12.
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.