2026 Ericsson US — 15,661 individuals (third-party vendor vishing)
Data compromised
Names, SSNs, addresses, driver's licenses, government IDs, financial info, medical info, DOB
Technical writeup
Ericsson Inc., the U.S. subsidiary of Swedish telecom giant Ericsson, disclosed a data breach affecting 15,661 employees and customers. Attackers gained access through a vishing (voice-phishing) scam targeting a third-party service provider employee who handed over account access—personal data was held by the vendor and exposed via that compromise. Unauthorized access occurred April 17-22, 2025; discovered by vendor April 28, 2025; Ericsson notified November 10, 2025; public regulatory filings and consumer notices intensified in March 2026, highlighting delayed disclosure from the vendor compromise window. Exposed: names, SSNs, addresses, driver's licenses, government IDs, financial information (bank/credit card numbers), medical information, dates of birth. Ericsson offered 12-24 months complimentary credit monitoring. FBI notified.
Root cause
Third-party service provider breach; vishing (voice-phishing) enabling unauthorized access
References
- https://www.bleepingcomputer.com/news/security/ericsson-us-discloses-data-breach-after-service-provider-hack/
- https://www.theregister.com/2026/03/10/ericsson_blames_vendor_vishing_slipup/
- https://www.classaction.org/data-breach-lawsuits/ericsson-march-2026
- https://www.claimdepot.com/data-breach/ericsson-2026