A new ransomware-as-a-service group called BYOD has posted personal data on 3,615 Trump Mobile customers to its dark web leak site. The group says it got in through a malware-infected employee at Liberty Mobile, the Florida-based MVNO that runs Trump Mobile's service. Neither Trump Mobile, Liberty Mobile nor the Trump Organization has confirmed the breach or answered press questions, according to SC Media. None of the sources is a primary statement from the victim, a regulator or a CERT. Several outlets have checked the data on their own, though. Straight Arrow News (SAN) and PCMag reached customers who confirmed their records were accurate, and Cybernews researchers said the samples looked legitimate and did not match earlier breaches. Treat this as a claimed breach with strong independent corroboration, not a confirmed incident.
What Happened
SAN reporter Mikael Thalen spotted the Trump Mobile listing on BYOD's leak site and reported the leak on October 5, 2026. PCMag, Cybernews, The Register (via SC Media), Mobile World Live and Biometric Update followed. All of them say the data went up "last week," which puts the posting in the final days of September or the first days of October.
In its leak-site statement, BYOD said that when it told Trump Mobile about the breach, the company replied "We have no team to handle this" and called anyone who hacked it "a terrorist." The only source for that exchange is BYOD. The company has not confirmed or denied it. Thalen later talked to the group over the encrypted messenger Session. BYOD told him it still had access as of Monday, October 5, and sent a screenshot of what it said was the internal dashboard staff use to look up customer records. It made the same claim of "live access to the dashboard" to PCMag and Cybernews.
Politicians have also picked up the story. On October 8, Sen. Maggie Hassan (D-N.H.) wrote to Trump Mobile CEO Patrick O'Brien. Ars Technica reports that her letter cites the breach and the alleged "no team" reply. It also says Trump Mobile appears to lack FCC authorization for its international calling service and has not filed a required robocall mitigation plan, and that Liberty Mobile Wireless's robocall database filing is incomplete.
This is not the company's first exposure. Ars Technica notes that Trump Mobile previously confirmed a vendor had exposed customer data online, which SAN and SC Media connect to a website flaw found in May. SC Media also mentions an earlier leak by a group called EndZone. Biometric Update describes an unverified September claim by a different extortion group to hold data on about 4,000 users, including eSIM QR codes. The sources don't say whether the EndZone leak and the September claim are the same event, or whether either is connected to BYOD.
What Was Taken
SAN, PCMag, SC Media, Cybernews and Biometric Update all describe the same fields: first and last names, email addresses, phone numbers, home addresses and order or purchase details. BYOD also says the dump includes unspecified "telecom details."
- Volume: Every source gives 3,615 records. One sentence in Cybernews rounds this to "almost 4,000," but its own headline and key takeaways say 3,615. Don't confuse this with the separate, unverified September claim of about 4,000 users that Biometric Update reports.
- Scope: BYOD told PCMag that 3,615 is the whole subscriber base on the MVNO service. It says that group is separate from the much larger pool of people who put down deposits on the T1 phone. Estimates of that pool range from 590,000 (SAN) to about 600,000 (Mobile World Live).
- Notable exposure: SAN, Cybernews and SC Media all report that the leak includes personal details of Eric Brunnett, VP and CIO of the Trump Organization, whose LinkedIn profile says he oversees all of its IT and information security. SAN found no Trump family members in the data.
- Verification: Thalen says he phoned several people in the file and those he reached confirmed the data was accurate. Three others said they had never used Trump Mobile and hung up. PCMag separately reached three customers, and one confirmed the file correctly showed they had cancelled a "30 Day Unlimited Talk Text Data" plan. SAN found that some records show $100 device deposits from 2025 and others show $55 to $65 monthly plans.
The data includes no payment card numbers or government IDs. But names, phone numbers, home addresses and carrier account details together are exactly what an attacker needs for SIM-swap fraud, carrier social engineering and targeted phishing.
Why It Matters
MVNO trust chains are an attack surface. Trump Mobile depends on Liberty Mobile for much of its infrastructure. If BYOD's account is accurate, the attackers compromised the partner and then moved into the brand's own systems. Companies that hand operations to a white-label provider still carry the risk.
Telecom PII enables account takeover. Hassan's letter says Trump Mobile's customer authentication looks weak and its streamlined activation could make it easier for scammers to get US numbers. Combined with a leaked subscriber list, that weakness makes SIM swapping and number porting fraud more likely for the people exposed.
Executive exposure through personal accounts. The Trump Organization's CIO turning up in a consumer leak shows how security leaders' personal service accounts can leak data about high-value targets, whatever controls exist at their employer.
Incident response readiness. No one has verified the "no team to handle this" reply. Still, the lack of any public statement after a week of coverage, on top of earlier exposures, suggests the company has no working way to receive and act on breach notifications.
The Attack Technique
The only account of the intrusion path comes from BYOD. Biometric Update notes that no public forensic evidence yet backs up the entry point, the missing MFA or the claim of ongoing access.
- Initial access: BYOD told PCMag it "ratted a Liberty Mobile employee," meaning it installed a Remote Access Trojan. SAN and Biometric Update give the same account. SC Media, citing The Register, calls the malware an infostealer. Accounts differ. A RAT gives live remote control, while an infostealer harvests credentials and session tokens. Either way, the result was access through an employee's credentials or session.
- Privilege and pivot: According to BYOD, the compromised account could only look up prepaid numbers, so it "pivoted to subdomains" belonging to Trump Mobile that were exposed and pulled customer data from them.
- Authentication: BYOD told International Cyber Digest (via Biometric Update) that neither Trump Mobile nor Liberty Mobile used multi-factor authentication on the affected systems. SC Media repeats the claim. It has not been verified.
- Persistence: BYOD says it still has access to the admin dashboard and has shared screenshots with journalists. Nobody outside the group has confirmed that access continues.
What Organizations Should Do
- Require phishing-resistant MFA on every customer-data console, including internal lookup tools that partners and MVNO staff use. Use FIDO2 or passkeys rather than SMS where you can.
- Inventory and lock down your subdomains. Enumerate everything internet-facing, take down staging and admin hosts that don't need to be public, and put the rest behind identity-aware access.
- Treat outsourced operators' endpoints as part of your perimeter. Contractually require EDR, infostealer and RAT detection, and fast credential revocation for any third-party staff who can touch your customer systems.
- Bind sessions and watch for token reuse. Infostealers and RATs hijack live sessions, so use short session lifetimes, device-bound tokens, and alerts for dashboard logins from new hosts or odd locations.
- Add carrier-grade account protections after a leak. Turn on port-out PINs, number-lock and stronger identity checks for SIM changes on affected accounts, and tell customers about the SIM-swap risk.
- Keep a working disclosure channel. Run a monitored security contact (security.txt, a dedicated inbox) and an incident response retainer so extortion notices and researcher reports reach someone who can act.
Sources: My chat with a hacker who breached Trump Mobile | Trump Mobile doesn't seem to have FCC authorization for phone servi... | Ransomware group BYOD claims Trump Mobile data breach | Hackers: We Stole Data From 3,615 Trump Mobile Customers | Trump Mobile’s latest problem: Hackers just released customer infor... | Trump Mobile data breach exposes 3,615 users Cybernews | Hackers leak Trump Mobile customer data | Trump Mobile breach exposes customer data as earlier security ...