HomeSecurityEricsson in the US reveals data breach

Ericsson in the US reveals data breach

Ericsson Inc., the U.S. subsidiary of Swedish telecommunications giant Ericsson, recently disclosed a data breach that affected the personal information of employees and customers. The leak originated not from the company's internal systems, but from an external service provider that managed files with sensitive data.

Ericsson

The parent company, headquartered in Stockholm and with a history dating back to 1876, is one of the world's leading players in telecommunications and network infrastructure. With around 90,000 employees worldwide, Ericsson plays a critical role in the development of 5G technologies and advanced telecommunications services. The recent incident highlights that even the largest organizations are not immune to cybersecurity risks, especially when third-party partners are involved.

Ericsson Inc.: How the data breach was detected

According to notifications sent to affected individuals and filed with California authorities, the breach was detected on April 28, 2025, by the service provider that maintained the records. After the suspicious activity, security incident response procedures were immediately.

See also: UNC4899 hacked crypto company after employee scam

The provider notified the FBI and hired specialized cybersecurity consultants to investigate the incident. The goal of the investigation was to determine both the scope of the breach and the type of data the attackers may have obtained.

The analysis was completed in February 2026 and indicated that a subset of files may have been compromised between April 17 and 22, 2025. Although the company did not disclose the total number of people affected, it confirmed that personal data was contained in the files examined.

Ericsson in the US reveals data breach

What data was exposed?

The information that was potentially exposed includes a wide range of personal information. These include names, home addresses and dates of birth, as well as more sensitive data such as social security numbers, driver's license numbers and other government identification numbers, such as passports or state IDs.

Additionally, in some cases, financial information, such as bank account numbers or credit and debit card details, was included. At the same time, the records may have also contained medical data, which increases the seriousness of the breach, as such information is considered particularly sensitive.

See also: ShinyHunters claim to be stealing data from Salesforce Aura

A separate filing with the Texas Attorney General revealed that at least 4,377 people were affected in that state alone . The actual number is likely higher, as the incident involves multiple geographic areas.

Protection measures for the affected

In an effort to mitigate the potential impact of the breach, Ericsson is offering free identity protection services to affected users. The services are provided through the IDX and include credit report monitoring, dark web activity, identity recovery services in the event of fraud, and insurance coverage of up to $1 million for identity theft losses.

Interested parties can register for the protection program until June 9, 2026. Similar initiatives have now become standard practice in large companies after data breach incidents, as the theft of personal information can lead to financial fraud or identity misuse for an extended period after the event.

Lack of accountability from hacker groups

One element that raises questions is the fact that no known cybercriminal group has so far claimed responsibility for the attack. In many modern ransomware or data theft, perpetrators publicize responsibility in order to pressure victims into paying the ransom.

See also: Netherlands: Russian hackers breach Signal, WhatsApp accounts of officials

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Ericsson in the US reveals data breach

The absence of such an announcement creates various possible scenarios. One of them is that the service provider may have paid a ransom to prevent the disclosure of the data. Another possibility is that the attackers failed to link the breach to Ericsson, resulting in them not using it as a leverage for extortion.

The risks from partner chain attacks in the supply chain

The incident highlights a major cybersecurity issue: the risk posed by so-called supply chain attacks . In such cases, attackers do not directly attack the main organization, but rather a partner or supplier that has access to critical data.

For large technology and telecommunications companies that work with dozens or even hundreds of external service providers, the security of the partner chain is now a critical factor. Even if internal systems are well protected, a weak connection to a third-party partner can create a serious security gap.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS