Hacker Group Claims Theft of Trump Mobile Customer Data
Key Takeaways A ransomware group, BYOD, claims to have breached Trump Mobile, leaking customer data on the dark web. The exposed dataset reportedly contains 3,615 records, including names, addresses,...
Key Takeaways
- A ransomware group, BYOD, claims to have breached Trump Mobile, leaking customer data on the dark web.
- The exposed dataset reportedly contains 3,615 records, including names, addresses, emails, and phone numbers.
- The authenticity of some records has been confirmed by individuals listed in the leak.
- BYOD alleges it gained access via malware infecting an employee at Liberty Mobile and claims ongoing backend access.
- No Trump family members were found in the leaked data, but a senior Trump Organization executive’s details were present.
Ransomware Group Alleges Trump Mobile Breach, Leaks Customer Data
A ransomware collective known as BYOD has asserted responsibility for a data breach impacting Trump Mobile customers, subsequently publishing sensitive personal information on a dark web leak site. The disclosed file purportedly contains 3,615 distinct records, encompassing individual names, email addresses, telephone numbers, residential addresses, and specific order details.
Table Of Content
The incident came to light on October 5, 2026, when Straight Arrow News investigated the leaked data. Their review involved cross-referencing the information and directly contacting individuals whose details appeared in the dataset. While several contacted individuals corroborated the accuracy of their personal information, some denied being Trump Mobile customers. This validation supports the legitimacy of a portion of the records, though it does not confirm every entry within the exposed data.
Notably, the leaked information reportedly includes details belonging to Eric Brunnett, who serves as the Vice President and Chief Information Officer for the Trump Organization. His responsibilities encompass the technological and information security infrastructure of the broader organization. Straight Arrow News confirmed that no members of the Trump family were identified within the compromised dataset.
Alleged Malware Infection as Entry Point
A representative from the BYOD group informed Straight Arrow News that their access was secured after an employee at Liberty Mobile, a Florida-based entity, became infected with malware. Trump Mobile operates under the ownership of T1 Mobile and leverages branding licensed from the Trump Organization.
BYOD further claimed to retain active access to Trump Mobile’s backend dashboard, providing a screenshot purportedly displaying customer information as evidence. As of this report, the specific malware family utilized, the precise method of infection, and the detailed access path have not been publicly substantiated. Furthermore, the report does not offer confirmed evidence that ransomware was deployed to encrypt company systems.
The attackers alleged that Trump Mobile responded to their breach notification with the statement, “We have no team to handle this.” This account remains solely the claim of the attackers. Trump Mobile had not issued a response to Straight Arrow News’s request for comment when it published its report.
The exposure of contact and order details presents a significant risk, as malicious actors could leverage this information to construct highly convincing phishing messages, fabricate payment requests, or initiate fraudulent calls impersonating customer support. Cybersecurity News previously highlighted similar risks following the Odido telecom data breach, underscoring the potential for social engineering attacks.
A critical unresolved question pertains to the veracity and ongoing nature of the claimed backend access. Until this claim can be independently verified, the full extent of the alleged Trump Mobile data breach, including the possibility of further data exposure, remains uncertain.
What You Should Do
- Be extremely wary of any unsolicited communications, including emails, text messages, or phone calls, claiming to be from Trump Mobile or related services.
- Always verify the authenticity of unexpected messages or requests for information through official channels (e.g., the company’s official website or customer service number) and not by replying to the suspicious communication.
- Never share passwords, one-time passcodes, or account verification codes with callers or in response to suspicious messages.
- Monitor your financial statements and credit reports for any unusual activity.
- Consider enabling multi-factor authentication (MFA) on all your online accounts where available to add an extra layer of security.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.