Home / The Long Read / Threat Intelligence
Threat IntelligenceLong Read

UBS and DSM-Firmenich hit by employee data theft in major cyberattack

UBS and DSM-Firmenich data breach exposes 7.9M employees. Learn how proactive vendor risk management can prevent third-party vulnerabilities.

Article contents
  1. How did the breach happen?
  2. What was leaked?
  3. Global impact of the attack
  4. How companies can protect themselves
UBS and DSM-Firmenich hit by employee data theft in major cyberattack
TL;DR

UBS and DSM-Firmenich data breach exposes 7.9M employees. Learn how proactive vendor risk management can prevent third-party vulnerabilities.

In another alarming incident of cybercrime, UBS and DSM-Firmenich have confirmed that sensitive employee data was stolen due to a breach involving their IT service provider. According to Swiss newspaper Le Temps, this breach was part of a larger cyberattack affecting 27 multinational companies, including Amazon, McDonald’s, Lenovo, HSBC, and Delta, with 7.9 million employees impacted globally.

How did the breach happen?

The cyberattack originated from vulnerabilities in the MOVEit software, a widely used data transfer tool provided by Progress Software. The software had known issues since last year, which cybercriminals exploited to gain unauthorized access to sensitive information. MOVEit’s vulnerabilities have now left a staggering trail of breached data, including the personal information of 20,462 UBS employees and 13,248 employees at DSM-Firmenich.

What was leaked?

DSM-Firmenich confirmed that the leaked data primarily involved employees from its former Firmenich division. The information included first and last names, outdated meeting room names, and defunct email addresses. Thankfully, no client or financial data was affected. In response, DSM-Firmenich assured the public that it has reinforced its data security measures.

For UBS, Le Temps reports that data on over 20,000 employees appeared on the darknet. However, UBS declined to comment further on the incident.

Global impact of the attack

This breach highlights the far-reaching consequences of third-party vulnerabilities. With 27 major companies and millions of employees affected, the MOVEit vulnerability underscores how a single software issue can cascade into a global cybersecurity crisis.

These incidents reiterate the importance of proactive vendor risk management. Companies can no longer afford to rely solely on their internal security but must also monitor and audit their IT service providers. Solutions like Supplier Shield enable businesses to identify and address third-party risks before they lead to significant breaches.

How companies can protect themselves

This incident serves as a critical reminder for businesses to proactively address third-party risks. Many breaches, like the one involving MOVEit, stem from vulnerabilities in external vendors’ systems. Companies can safeguard their operations by conducting regular audits, monitoring vendor security practices, and responding quickly to detected vulnerabilities.

Supplier Shield helps businesses achieve this by providing comprehensive third-party risk management solutions. Through continuous monitoring of vendor systems, early detection of vulnerabilities, and actionable insights, Supplier Shield enables companies to identify risks before they escalate. By partnering with solutions like this, organizations can strengthen their supply chain defenses and reduce the likelihood of being impacted by similar breaches.

What to do next

Want this applied to your supplier ecosystem? See the platform in action and map your top vendor risks live in one walkthrough.

Related solutions
How Supplier Shield worksCompare alternatives

Read next

ChainDrop npm worm hits 400-plus packages: one stolen login becomes a self-spreading supply-chain attack

ChainDrop npm worm hits 400-plus packages: one stolen login becomes a self-spreading supply-chain attack

A self-propagating worm named ChainDrop infected more than 400 npm packages, including keyv, flat-cache and cache-manager, Microsoft reported on 4 August 2026. The malware steals developer and cloud credentials, then uses stolen publishing tokens to poison further packages on its own. For third-party risk teams, it is a fourth-party exposure most vendor registers never capture.

Read article
Amgen says patient data was stolen from third-party cloud systems, not its own network

Amgen says patient data was stolen from third-party cloud systems, not its own network

Amgen told the US SEC that attackers stole patient health information and proprietary company data from cloud systems run by external service providers, not from its own network. The company concluded the incident was material on 29 July 2026. It says medicine supply was not affected. The lesson: data placed in a supplier's cloud is still the owner's breach to disclose.

Read article
Xsolis breach reached hospital patients through one shared healthcare AI vendor

Xsolis breach reached hospital patients through one shared healthcare AI vendor

A phishing attack at Xsolis, a US healthcare vendor that many hospitals and insurers use to review whether care is covered, exposed the data of about 1.4 million people. Patients at Mayo Clinic, UW Medicine and VHC Health were among those affected, because one vendor held records from many providers at once.

Read article