HackingSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICLowContained
Ericsson Inc.
bd_3ac020b40fae811c · schema v1 · pii pii-v1
Full breach record for Ericsson Inc. →Ericsson Inc notified the California AG of a data security incident at a third-party service provider. Unauthorized access to certain data occurred between April 17 and April 22, 2025. The provider detected the suspicious event on April 28, 2025. A review completed on February 23, 2026, determined that some personal information (name and other data elements) was contained in the affected files. Ericsson is offering identity protection services to affected individuals.
California clockDiscovered Apr 28, 2025 → Notified Mar 9, 2026315d ✗ CA 60-day late45 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_1d0da259aa372497Maine State AGfiled 2026-03-09Candidate
- bd_4b391d16ed54393eNew Hampshire State AGfiled 2026-03-09Verified
- bd_b7aab07b8740f441Texas State AGfiled 2026-03-09Verified
- bd_b9339ad22885050fVermont State AGfiled 2026-03-09Verified
Show 1 more filing ↓Show fewer ↑
- bd_f086a2ecb41cecd3Indiana State AGfiled 2026-03-09Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-619823
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 9, 2026
- Raw hash
- ea9854579f818578328719d353a8984ef12fe9da104606512b91a09f586c4ea5
Reporting entity
- Name
- Ericsson Inc.norm: ericsson
- Domain
- ericsson.com
Victim entity
- Name
- Ericsson Inc.norm: ericsson
- Domain
- ericsson.com
Incident
- Discovered
- Apr 28, 2025
- Materiality determined
- —
- Notification sent
- Mar 9, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation
- Third party
- via Service Provider
Compliance
- Time to disclose
- 45 weeks(315 days from discovery to filing)
- Compliance flags
- CA 60-day late · 315dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 28, 2025→ Notified: Mar 9, 2026315d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Mar 9, 2026→ AG copy submitted: Mar 9, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.