Ericsson Inc., the U.S. subsidiary of the multinational telecommunications company Telefonaktiebolaget LM Ericsson, announced a data breach involving one of its service providers. The incident was discovered on April 28, 2025, with unauthorized access occurring between April 17-22, 2025. Ericsson emphasized that the breach did not occur within Ericsson's own systems and the service provider has no evidence of misuse of the impacted information.
The breach affected 15,661 Ericsson employees and customers. Exposed data types include Names, Addresses, Social Security Numbers, Driver's License numbers, Government-issued ID numbers (passports, state IDs), Financial information (account numbers, credit/debit card numbers), Medical information, and Dates of birth. The identity of the third-party service provider involved in the breach has not been disclosed, and specific details about the individuals or entities responsible for the unauthorized access are not publicly available.
Ericsson notified affected individuals and filed with state attorneys general on February 24, 2026. The company offering affected individuals free identity protection services, including credit monitoring, dark web monitoring, identity theft recovery assistance, and a $1 million identity fraud reimbursement policy for those who enroll.