Data leak
β Supply Chain
Ericsson US Third-Party Service Provider Data Breach
Primary Source βIncident Details
Between April 17β22, 2025, an unknown threat actor accessed files at an unnamed third-party service provider used by Ericsson Inc. (US operations). The investigation concluded in February 2026, and Ericsson notified approximately 15,000 affected individuals in March 2026. A filing with the Texas AG on March 9, 2026 indicated 4,377 Texas residents were impacted. Exposed data included names, addresses, Social Security numbers, driver’s license numbers, passport numbers, state ID numbers, and financial account/card numbers. No cybercrime group has claimed responsibility. Ericsson offered 12 months of identity protection via IDX to affected individuals.
Technical Details
- Initial Attack Vector
- Unauthorized access to an unnamed third-party service provider's systems that stored Ericsson employee and customer data
- Vendor / Product
- Unnamed third-party service provider
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2025-04-17 Breach occurred
- 2026-03-09 Publicly disclosed
- 2026-03-09 Customers notified