DisclosureLens
Social EngineeringTelecom & MediaInformationVishingData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)Identity (basic)Government IDMediumContained

Ericsson Inc.

bd_4b391d16ed54393e · schema v1 · pii pii-v1

Severity

Medium

Discovered

Apr 28, 2025

Filed

Mar 9, 2026

To disclose

45 weeks

Affected

97state residents only

Linked

8 filings

Confidence

66%
Full breach record for Ericsson Inc.2 incidents on file

Ericsson Inc. notified the New Hampshire Attorney General of a data security incident involving a third-party service provider. The provider experienced a vishing attack on April 28, 2025, leading to unauthorized access to limited data between April 17 and April 22, 2025. Approximately 97 New Hampshire residents were affected, with potential exposure of names and Social Security numbers. Ericsson engaged cybersecurity experts, reset passwords, notified the FBI, and provided 12 months of credit monitoring to affected individuals.

Incident timeline

undetected · 11 days
discovery → filing · 45 weeks / 315 days

Apr 17, 2025

Begins

Apr 28, 2025

Discovered

Mar 9, 2026

Filed

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filings

Filing propagation · 8 filings · 8 states

View merged incident ↗
Maine State AGMar 9 · first
California State AGMar 9 · first
Texas State AGMar 9 · first
Vermont State AGMar 9 · first
Nebraska State AGMar 9 · first
Indiana State AGMar 9 · first
New Hampshire State AGMar 9 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.