Ericsson US Hit by Cyber Attack, Hackers Steal Personal Data of Employees and Customers
Ericsson Inc., the United States subsidiary of the Swedish telecommunications company, has reported a data breach impacting 15,661 employees and customers. The breach occurred through a third-party service provider responsible for managing sensitive…
Ericsson Inc., the United States subsidiary of the Swedish telecommunications company, has reported a data breach impacting 15,661 employees and customers. The breach occurred through a third-party service provider responsible for managing sensitive personal data.
The breach originated from an attack on a service provider supporting Ericsson's US operations. The attackers used a "vishing" (voice phishing) strategy, a form of social engineering where an employee is deceived over the phone to gain system access. This compromised access allowed the attackers to infiltrate the vendor's files from April 17, 2025, to April 22, 2025. The vendor identified the suspicious activity on April 28, 2025, and initiated an investigation with external cybersecurity experts. Ericsson was notified of the data exposure on November 10, 2025. A thorough review to determine the victims and the exposed data concluded on February 23, 2026.
According to state filings, the exposed information includes:
Full names, addresses, and dates of birth Social Security Numbers (SSNs) and driver’s license numbers Government-issued IDs, including passports and state identification cards Financial data, such as bank account numbers and credit or debit card details Sensitive medical information
Ericsson Inc., the United States subsidiary of the Swedish telecommunications company, has reported a data breach impacting 15,661 employees and customers.
Although no ransomware group has claimed responsibility, Ericsson and its vendor have implemented several measures to manage the threat:
Law Enforcement Involvement: The third-party vendor contacted the Federal Bureau of Investigation (FBI) to trace the threat actors. System Hardening: The vendor enforced mandatory password resets, enhanced security measures, and increased staff cybersecurity training to mitigate future social engineering attacks. Identity Protection: Ericsson is offering impacted individuals free identity protection through IDX, which includes dark web monitoring, credit monitoring, and a $1 million identity fraud loss reimbursement policy. Affected users must enroll by June 9, 2026, to take advantage of these services.
This incident underscores the cybersecurity risks associated with supply chains and third-party vendors. Even if a company like Ericsson secures its internal systems, attackers may exploit vulnerabilities in the supply chain using effective tactics like vishing. It is crucial for organizations to remain vigilant, as stolen data from such breaches can be used for identity theft or financial fraud. Impacted employees and customers are advised to monitor their bank statements and place fraud alerts on their credit profiles.
Based on reporting by GBHackers.
