[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1ZM-588Pu9e95cxP3kuJoivJjmg1SMJfOD6ZtFUeims":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":27,"source":28,"isVerified":4,"isSpamList":29,"isSensitive":4,"severity":30,"processingStatus":31,"logoUrl":32,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66b2322dd4f325176bf65f","EricssonUSServiceProvider2025","Ericsson US Service Provider 2025 Data Breach","ericsson-us-service-provider-2025","ericsson.com",{"name":12,"sector":13,"country":14,"website":10},"Ericsson Inc.","Telecommunications","United States","2025-04-17T00:00:00.000Z","2026-07-27T01:19:46.527Z",15661,[19,20,21,22,23,24,25,26],"Names","Physical addresses","Social Security numbers","Driver's license numbers","Government-issued identification numbers","Financial information","Medical information","Dates of birth","\u003Cp>\u003Cstrong>The Ericsson US Service Provider 2025 data breach\u003C\u002Fstrong> affected 15,661 people after an unnamed service provider holding personal information for Ericsson Inc. employees and customers was attacked. The investigation determined that a limited subset of files may have been accessed or acquired without authorization between April 17 and April 22, 2025.\u003C\u002Fp>\n\u003Cp>The service provider discovered the incident on April 28, 2025, notified the FBI, and opened an investigation with external cybersecurity specialists. A comprehensive review to identify personal information in potentially affected files was completed on February 23, 2026. Ericsson then notified affected individuals and disclosed the total through filings with state regulators.\u003C\u002Fp>\n\u003Ch2>How Was the Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>Ericsson's sample notification filed with California's Attorney General explains that the provider stored personal information for Ericsson employees and customers and that certain files may have been accessed or acquired without authorization. The Maine Attorney General record gives the affected total as 15,661. These documents establish a company-reported third-party breach rather than only an attacker allegation.\u003C\u002Fp>\n\u003Cp>BleepingComputer compared the regulatory filings and published the access window, investigation dates, person total, and data categories listed in the Texas report. An Ericsson spokesperson offered no details beyond the letter. Because no cybercrime group was identified, LeakData adds no attacker name, ransom claim, or definitive initial-access method.\u003C\u002Fp>\n\u003Ch2>What Information Was Affected?\u003C\u002Fh2>\n\u003Cp>Depending on the individual, state filings list names, physical addresses, Social Security numbers, driver's license numbers, and government identification numbers such as passports or state ID cards. They also list financial information such as account numbers and credit or debit card numbers, medical information, and dates of birth. Not every data type should be assumed to have appeared for all 15,661 people.\u003C\u002Fp>\n\u003Cp>These fields can enable identity theft, fraudulent account opening, account takeover, and targeted scams. Because the regulatory filing describes financial information broadly, LeakData does not infer that PINs, CVVs, passwords, or security questions were present. Medical information also remains a general class because no particular diagnosis, treatment, or prescription detail was disclosed.\u003C\u002Fp>\n\u003Ch2>Why Does the Third-Party Provider Matter?\u003C\u002Fh2>\n\u003Cp>The affected system belonged to a service provider storing employee and customer data on Ericsson's behalf rather than the company's primary network. Ericsson Inc. nevertheless has a direct relationship to the data and the notifications sent to victims. LeakData therefore keeps the event in the Ericsson US context while clearly identifying the source as a third-party service provider.\u003C\u002Fp>\n\u003Cp>The provider was not named in the public notice. That omission does not justify guessing a vendor or automatically associating other possible customers with the incident. This record represents only the scope confirmed for Ericsson employees and customers in the regulatory documents and does not treat the parent company's entire global workforce as affected.\u003C\u002Fp>\n\u003Ch2>How Is the 15,661-Person Figure Used?\u003C\u002Fh2>\n\u003Cp>The Maine regulatory record reports a total of 15,661 affected individuals, so pwnCount and totalRecords use that same verified value. The figure was not inferred from Ericsson's approximate global workforce, customer base, or stored-file volume. The incident total in the state record is preferred over rounded headlines saying more than 15,000.\u003C\u002Fp>\n\u003Cp>The total does not mean each data class occurred 15,661 times. Notices indicate that fields could vary by person and that the files covered both employees and customers. Because no category-level distributions were published, LeakData does not invent subtotals for people whose medical, financial, or government-identification information was involved.\u003C\u002Fp>\n\u003Ch2>Company Response and Steps for Individuals\u003C\u002Fh2>\n\u003Cp>The provider notified the FBI, retained external cybersecurity specialists, and reviewed the affected files. Ericsson offered notified people IDX identity protection, credit monitoring, dark-web monitoring, identity-theft recovery assistance, and up to one million dollars in identity-fraud loss reimbursement coverage. The provider said it had found no evidence of misuse at the time of the notice.\u003C\u002Fp>\n\u003Cp>Affected people should enroll in the offered protection before its deadline, review credit reports and bank or card activity, and dispute unfamiliar applications. Those whose Social Security or government-ID data was involved may consider fraud alerts or a credit freeze. A statement that no misuse has been detected does not eliminate future risk.\u003C\u002Fp>\n\u003Ch2>How Should This LeakData Record Be Read?\u003C\u002Fh2>\n\u003Cp>This record uses April 17, 2025, the beginning of the unauthorized file-access window, as breachDate. The event was discovered on April 28, the data review ended on February 23, 2026, and public notices followed in March 2026. The interval does not imply one continuous attack; it reflects the time required to investigate files and identify affected individuals.\u003C\u002Fp>\n\u003Cp>The verified total is 15,661 Ericsson Inc. employees and customers. Depending on the person, fields may include names, addresses, Social Security numbers, driver's licenses and other government IDs, financial information, medical information, and dates of birth. The provider, attacker, and exact access method were not disclosed, so the record does not speculate about them.\u003C\u002Fp>","Unauthorized access to or acquisition of files held by a third-party service provider",false,"Medium","completed","\u002Fuploads\u002Flogo\u002Fericsson_com.svg"]