Ericsson US discloses data breach after service provider hack
嗯,用户让我帮忙总结一篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头。直接写描述就行。 首先,我需要仔细阅读文章。文章讲的是爱立信美国分公司被黑客攻击,导致员工和客户的资料被盗。攻击者入侵了他们的一个服务提供商,窃取了数据。事件发生在2025年4月28日,调查发现一些个人资料被泄露,但目前还没有证据显示数据被滥用。 接下来,文章提到受影响的人数在得克萨斯州有4377人,泄露的信息包括姓名、地址、社会安全号码、驾照号码、政府颁发的ID、财务信息、医疗信息和出生日期。爱立信正在提供免费的身份保护服务。 此外,没有网络犯罪集团声称对此负责,这可能意味着服务提供商支付了赎金或者威胁行为者无法将此次入侵与爱立信联系起来。 现在我要把这些信息浓缩到100字以内。重点包括:爱立信美国分公司被攻击,数据泄露影响员工和客户,涉及敏感个人信息如SSN、驾照号等,服务提供商可能支付赎金或未被追踪到。 需要注意的是,不要使用“文章内容总结”这样的开头,直接描述事件即可。 </think> 爱立信美国分公司遭遇数据泄露事件,员工及客户敏感信息如社保号、驾照号等被盗,涉及人数众多,部分数据或已被获取,但尚未发现滥用迹象,服务提供商可能支付赎金或未被追踪到。 2026-3-9 19:15:17 Author: www.bleepingcomputer.com(查看原文) 阅读量:4 收藏

Ericsson

Ericsson Inc., the U.S. subsidiary of Swedish networking and telecommunications giant Ericsson, says attackers have stolen data belonging to an undisclosed number of employees and customers after hacking one of its service providers.

Headquartered in Stockholm and founded in 1876, the parent company is a communications tech leader with nearly 90,000 employees worldwide.

In data breach notification letters sent to affected individuals and filed with the California Attorney General on Monday, Ericsson said that a service provider who was storing personal data for employees and customers discovered a breach on April 28, 2025.

After detecting the incident, the service provider notified the FBI and hired external cybersecurity experts to assess the extent of the breach and its impact.

The investigation, which was completed last month, found that an undisclosed number of individuals had their data exposed in the incident. However, Ericsson noted that the compromised provider has yet to find evidence that the data has been misused since the breach.

"Based on the investigation, our service provider determined that a limited subset of files may have been accessed or acquired without authorization between April 17, 2025 and April 22, 2025," Ericsson said.

"As part of its investigation, it retained external data specialists to conduct a comprehensive review of the potential affected files to identify any personal information. That review was completed on February 23, 2026 at which time we determined that that some of your personal information was contained within the affected files."

According to a separate filing with the Texas Attorney General, the breach impacted 4,377 individuals in Texas alone, while the exposed information includes affected individuals' names, addresses, Social Security Numbers, Driver’s License numbers, government-issued ID numbers (e.g., passport, state ID cards), financial Information (e.g., account numbers, credit or debit card numbers), medical Information, and dates of birth.

Ericsson is now providing free IDX identity protection services, including credit monitoring, dark web monitoring, identity theft recovery, and a $1 million identity fraud loss reimbursement policy to affected people who enroll by June 9, 2026.

Although the company flagged this incident as a data theft attack, no cybercrime group has taken responsibility for the breach. This raises the possibility that either the service provider paid the ransom demanded by the attackers or that the threat actors were unable to connect the breach to Ericsson.

When BleepingComputer reached out for more details on the breach, including the total number of affected individuals, an Ericcson spokesperson said they didn't have "anything to share beyond the letter."

tines

Red Report 2026: Why Ransomware Encryption Dropped 38%

Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.


文章来源: https://www.bleepingcomputer.com/news/security/ericsson-us-discloses-data-breach-after-service-provider-hack/
如有侵权请联系:admin#unsafe.sh