Ericsson US Discloses Data Breach as Hackers Steal Employee and Customer Data

Ericsson Inc., the United States subsidiary of Swedish telecommunications giant Ericsson, has disclosed a data breach that exposed sensitive personal and financial information belonging to 15,661 employees and customers.

The incident was not caused by a compromise of Ericsson’s internal infrastructure but instead resulted from a security breach at a third‑party service provider responsible for processing and storing sensitive data related to Ericsson’s U.S. operations.

Vishing Attack Enabled Unauthorized Access

According to regulatory filings submitted to U.S. authorities, the breach originated from a targeted cyberattack against the external vendor.

Threat actors successfully gained access to the vendor’s systems through a “vishing” (voice phishing) attack, a social engineering tactic where attackers impersonate trusted individuals over the phone to trick employees into revealing login credentials or granting system access.

Using this technique, the attackers were able to infiltrate the vendor’s systems and access files between April 17 and April 22, 2025.

The unauthorized activity went undetected for several days until the service provider discovered suspicious behavior on April 28, 2025.

Following the discovery, the vendor initiated an internal investigation and engaged external cybersecurity specialists to determine the scope of the intrusion and the type of data potentially exposed.

Despite the early detection by the vendor, Ericsson was not formally notified of the breach until November 10, 2025.

A detailed forensic investigation and data review process continued for several months to identify impacted individuals and the exact information exposed. The analysis concluded on February 23, 2026.

Sensitive Personal and Financial Data Exposed

The breach exposed a wide range of highly sensitive personal information belonging to Ericsson employees and customers.

Compromised data may include:

  • Full names, residential addresses, and dates of birth
  • Social Security Numbers (SSNs) and driver’s license numbers
  • Government-issued identification documents such as passports and state IDs
  • Financial information, including bank account numbers and credit or debit card details
  • Certain medical or health-related information

Although the attackers accessed this information, there is currently no evidence indicating that the stolen data has been misused or publicly leaked.

Following the breach discovery, both Ericsson and the affected service provider implemented several measures to contain the incident and strengthen security defenses.

Key response actions include:

  • Law enforcement notification: The vendor reported the incident to the Federal Bureau of Investigation (FBI) to assist in identifying and tracking the attackers.
  • Security improvements: The vendor enforced mandatory password resets, strengthened system security controls, and expanded cybersecurity awareness training to reduce the risk of social engineering attacks.
  • Identity protection services: Ericsson is offering affected individuals complimentary identity protection services through IDX. These services include credit monitoring, dark web monitoring, and identity fraud insurance coverage of up to $1 million. Impacted individuals must enroll before June 9, 2026.

The incident highlights the growing risks associated with supply chain and third‑party vendor relationships.

Even when large enterprises maintain strong internal security defenses, attackers can target external partners that may have weaker security controls.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories