Ericsson Inc. (US) disclosed a data breach after attackers compromised an unnamed third-party service provider supporting its US operations, with the intrusion attributed to a voice-phishing (vishing) social-engineering incident against a vendor employee. Regulatory filings indicate the vendor detected suspicious activity on April 28, 2025, assessed that unauthorized access to certain files may have occurred between April 17–22, 2025, and engaged external cybersecurity specialists, notified the FBI, and implemented containment measures including password resets. Ericsson reported that the exposed information included personal data for employees and customers; one filing cited potential exposure of names and Social Security numbers, while another suggested a broader set of impacted data elements.
Ericsson stated it was notified by the service provider months later (reported as November 10, 2025), and that the company’s subsequent review to identify affected individuals and obtain contact details concluded on February 23, 2026. Ericsson ultimately confirmed 15,661 individuals were affected and reported that, as of disclosure, it had not detected misuse of the exposed data. Separate reporting in the same news cycle described unrelated ransomware activity affecting an EV charger manufacturer and an unconfirmed ransomware claim against a US electric cooperative; those incidents are distinct from the Ericsson third-party breach.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
On March 10, 2026, Ericsson disclosed the third-party data breach through regulatory notifications and public reporting. The company said exposed data may include highly sensitive personal information, stated it had seen no evidence of misuse, and offered affected individuals identity protection or credit monitoring services.
On February 23, 2026, Ericsson finished its review of the affected files and determined that personal information tied to Ericsson employees and customers was included. Reporting later said the breach affected 15,661 individuals.
Ericsson Inc. was informed by the affected service provider about the incident after the vendor's investigation progressed. Reporting states Ericsson received notification on November 10, 2025.
On April 28, 2025, the service provider detected the incident and launched an investigation with external cybersecurity specialists. The provider also forced password resets, notified the FBI, and implemented additional security measures.
Attackers gained unauthorized access to files held by a third-party service provider supporting Ericsson's U.S. operations. Later reporting attributed the intrusion to a vishing-based social engineering attack against a vendor employee, with access occurring between April 17 and April 22, 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcego.theregister.com
Open sourceteiss.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.