DisclosureLens
Social EngineeringTelecom & MediaInformationVishingData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)Identity (basic)Government IDHealth (basic)MediumContained

Ericsson Inc.

bd_dcb9b2488cc2223a · schema v1 · pii pii-v2

Severity

Medium

Discovered

Apr 28, 2025

Filed

Mar 9, 2026

To disclose

Affected

34state residents only

Linked

8 filings

Confidence

66%
Full breach record for Ericsson Inc.2 incidents on file

Ericsson Inc, a telecommunications company, notified Nebraska AG that a third-party service provider experienced a vishing incident between April 17-22, 2025. The attack targeted a single service provider employee, leading to unauthorized access to limited data including names, SSNs, and health information. Approximately 34 Nebraska residents were notified on March 9, 2026. Ericsson engaged cybersecurity experts, reset passwords, notified the FBI, and provided 12 months of credit monitoring.

Incident timeline

undetected · 11 days

Apr 17, 2025

Begins

Apr 28, 2025

Discovered

Mar 9, 2026

Filed

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filings

Filing propagation · 8 filings · 8 states

View merged incident ↗
Maine State AGMar 9 · first
California State AGMar 9 · first
Texas State AGMar 9 · first
Vermont State AGMar 9 · first
Indiana State AGMar 9 · first
Nebraska State AGMar 9 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.