Social EngineeringVishingData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Ericsson Inc.
bd_4b391d16ed54393e · schema v1 · pii pii-v1
Full breach record for Ericsson Inc. →Ericsson Inc. notified the New Hampshire Attorney General of a data security incident involving a third-party service provider. The provider experienced a vishing attack on April 28, 2025, leading to unauthorized access to limited data between April 17 and April 22, 2025. Approximately 97 New Hampshire residents were affected, with potential exposure of names and Social Security numbers. Ericsson engaged cybersecurity experts, reset passwords, notified the FBI, and provided 12 months of credit monitoring to affected individuals.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_1d0da259aa372497Maine State AGfiled 2026-03-09Candidate
- bd_3ac020b40fae811cCalifornia State AGfiled 2026-03-09Verified by operator
- bd_b7aab07b8740f441Texas State AGfiled 2026-03-09Verified
- bd_b9339ad22885050fVermont State AGfiled 2026-03-09Verified
Show 1 more filing ↓Show fewer ↑
- bd_f086a2ecb41cecd3Indiana State AGfiled 2026-03-09Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/ericsson-20260309.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 9, 2026
- Raw hash
- 963c7ee437142758ca59081a3ed6c7a5b0c477834307515382bbf6e9c057cfbd
Reporting entity
- Name
- Ericsson Inc.norm: ericsson
- Domain
- ericsson.com
Victim entity
- Name
- Ericsson Inc.norm: ericsson
- Domain
- ericsson.com
Incident
- Discovered
- Apr 28, 2025
- Materiality determined
- —
- Notification sent
- Mar 9, 2026
- Affected individuals
- 97
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 45 weeks(315 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.