Social EngineeringTelecom & MediaInformationVishingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedData ExfiltratedDelayed DiscoveryPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Ericsson Inc.
bd_1d0da259aa372497 · schema v1 · pii pii-v1
Full breach record for Ericsson Inc. →Ericsson Inc. reported a data security incident originating at one of its service providers. A vishing attack on a single individual at the service provider on or around April 28, 2025 led to unauthorized access to files between April 17–22, 2025. Potentially compromised data included names and Social Security numbers. The review was completed February 23, 2026; 21 Maine residents were notified March 9, 2026. IDX credit monitoring offered for 12 months.
Maine clockDiscovered Feb 23, 2026 → Filed with AG Mar 9, 202614d ✓ ME AG ≤30d14 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_3ac020b40fae811cCalifornia State AGfiled 2026-03-09Verified by operator
- bd_4b391d16ed54393eNew Hampshire State AGfiled 2026-03-09Verified
- bd_b7aab07b8740f441Texas State AGfiled 2026-03-09Verified
- bd_b9339ad22885050fVermont State AGfiled 2026-03-09Verified
Show 1 more filing ↓Show fewer ↑
- bd_f086a2ecb41cecd3Indiana State AGfiled 2026-03-09Verified by operator
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/d920097e-fba8-455c-b632-c7e115e5eb15.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 9, 2026
- Raw hash
- b35969a4672f24f3e28bc7f85be0ef840b98979a6add0de93ee0d6c4ac232c35
Reporting entity
- Name
- Ericsson Inc.norm: ericsson
- Domain
- ericsson.com
- Industry
- Telecommunications
Victim entity
- Name
- Ericsson Inc.norm: ericsson
- Domain
- ericsson.com
- Industry
- Telecommunications
- Industry
- Telecom & Mediallm
Incident
- Discovered
- Feb 23, 2026
- Materiality determined
- Feb 23, 2026
- Notification sent
- Mar 9, 2026
- Affected individuals
- 21
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified Federal Bureau of Investigation
Compliance
- Time to disclose
- 14 days(14 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 14d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Feb 23, 2026→ Filed with AG: Mar 9, 202614d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.