← Ericsson

2026 Ericsson US — 15,661 individuals (third-party vendor vishing)

2026 15.7K records affected Share on X

Data compromised

Names, SSNs, addresses, driver's licenses, government IDs, financial info, medical info, DOB

Technical writeup

Ericsson Inc., the U.S. subsidiary of Swedish telecom giant Ericsson, disclosed a data breach affecting 15,661 employees and customers. Attackers gained access through a vishing (voice-phishing) scam targeting a third-party service provider employee who handed over account access—personal data was held by the vendor and exposed via that compromise. Unauthorized access occurred April 17-22, 2025; discovered by vendor April 28, 2025; Ericsson notified November 10, 2025; public regulatory filings and consumer notices intensified in March 2026, highlighting delayed disclosure from the vendor compromise window. Exposed: names, SSNs, addresses, driver's licenses, government IDs, financial information (bank/credit card numbers), medical information, dates of birth. Ericsson offered 12-24 months complimentary credit monitoring. FBI notified.

Root cause

Third-party service provider breach; vishing (voice-phishing) enabling unauthorized access

References