Outplacement Blunder Exposes 1,320 UBS Staff Names in Unencrypted Email
Published on 09/01/2026 at 12:03 | Editorial boerse-global.de
A routine career-transition program for departing UBS employees has spiralled into a serious data protection incident after a Swiss HR contractor circulated a confidential staff list to nearly 500 unintended recipients.
The breach occurred at LHH, the outplacement specialist owned by the Adecco Group, which had been engaged to support workers let go during the Zurich-based bank's recent restructuring wave. On 1 September 2026, the company confirmed that an unencrypted Excel file containing the names of 1,320 UBS employees had been emailed to 499 recipients — a distribution far beyond the intended audience.
What Was Exposed — and What Wasn't
LHH moved quickly to contain the fallout. The firm filed a mandatory report with the Swiss Federal Data Protection and Information Commissioner on the same day the breach became public, a legal requirement for incidents of this magnitude.
The company did offer some reassurance about the scope of the leak. According to LHH, the file contained only names — no passwords, financial records, or other sensitive credentials were included in the misdirected attachment.
Still, the exposure carries real weight. The list effectively reveals which individuals were enrolled in outplacement programmes, a detail that signals their employment status with UBS and their participation in the bank's redundancy process. For employees already navigating the stress of job loss, the erosion of confidentiality adds another layer of difficulty.
Handling sensitive workforce data is a serious responsibility, and so is protecting employees from workplace risks once they remain on your payroll. Many employers unknowingly leave gaps in their safety documentation that could prove costly during an inspection. A free toolkit with 41 ready-to-use templates and checklists helps you document hazards properly and stay compliant. Download the free Risk Assessment Toolkit
Outsourcing's Hidden Risks
The episode underscores a growing vulnerability in corporate restructuring: the heavy flow of personal data between banks and external HR providers. When organisations like UBS shed staff, they routinely hand over substantial datasets to specialised firms such as LHH to manage career counselling and job-search support.
Data protection specialists have long cautioned that accountability does not disappear when third parties are brought in. Sending unencrypted spreadsheet attachments via standard email is widely regarded within the industry as an avoidable lapse — one that secure file-sharing platforms or encrypted database access could have prevented outright.
Regulatory Scrutiny Ahead
Supervisory authorities are now expected to examine whether LHH's internal controls were robust enough to catch such an elementary error. Investigations of this kind typically probe the company's IT security protocols in depth, with an eye toward preventing repeat incidents on future assignments.
When operational failures expose personal data, the spotlight turns to how organisations manage risk across every function — including workplace safety. Over 37,000 UK businesses use a free Health & Safety Toolkit with risk assessments and checklists covering key regulations like COSHH and PUWER. Get the free Health & Safety Toolkit
For UBS, the matter is equally delicate. As the commissioning client, the bank has a vested interest in protecting the privacy of its former employees — particularly during high-profile workforce reductions, where reputational damage can compound operational challenges.
Whether LHH or its parent company, Adecco Group, will face legal consequences remains an open question. What is certain is that for the 1,320 individuals caught up in this leak, an already demanding career transition has just become considerably more complicated.
