Ericsson US disclosed a data breach affecting employees and customers after one of its service providers was compromised. The breach occurred between April 17-22, 2025, with data potentially accessed or acquired without authorization. The investigation, completed in February 2026, confirmed that personal information was exposed. The incident impacted 4,377 individuals in Texas alone, with exposed data including names, addresses, Social Security Numbers, Driver's License numbers, government-issued IDs, financial information, medical information, and dates of birth.
Reconnaissance
Targeting a Service Provider
likely
Attackers identified and targeted a service provider that stored personal data for Ericsson employees and customers, likely seeking a less defended entry point into Ericsson's network or data.