Cyber & AI intelligence
Wasteland.
Briefs indexed3093
Issues31
Published Mondays07:30 CT
▣ Breach TRUMP-MOBILE-DATA 2026-10-09

Trump Mobile: BYOD Ransomware Group Claims Theft of 3,615 Customer Records

"A new ransomware-as-a-service group called BYOD has posted personal data on 3,615 Trump Mobile customers to its dark web leak site. The group says it got in through a malware-infected employee at Liberty Mobile, the…"

A new ransomware-as-a-service group called BYOD has posted personal data on 3,615 Trump Mobile customers to its dark web leak site. The group says it got in through a malware-infected employee at Liberty Mobile, the Florida-based MVNO that runs Trump Mobile's service. Neither Trump Mobile, Liberty Mobile nor the Trump Organization has confirmed the breach or answered press questions, according to SC Media. None of the sources is a primary statement from the victim, a regulator or a CERT. Several outlets have checked the data on their own, though. Straight Arrow News (SAN) and PCMag reached customers who confirmed their records were accurate, and Cybernews researchers said the samples looked legitimate and did not match earlier breaches. Treat this as a claimed breach with strong independent corroboration, not a confirmed incident.

What Happened

SAN reporter Mikael Thalen spotted the Trump Mobile listing on BYOD's leak site and reported the leak on October 5, 2026. PCMag, Cybernews, The Register (via SC Media), Mobile World Live and Biometric Update followed. All of them say the data went up "last week," which puts the posting in the final days of September or the first days of October.

In its leak-site statement, BYOD said that when it told Trump Mobile about the breach, the company replied "We have no team to handle this" and called anyone who hacked it "a terrorist." The only source for that exchange is BYOD. The company has not confirmed or denied it. Thalen later talked to the group over the encrypted messenger Session. BYOD told him it still had access as of Monday, October 5, and sent a screenshot of what it said was the internal dashboard staff use to look up customer records. It made the same claim of "live access to the dashboard" to PCMag and Cybernews.

Politicians have also picked up the story. On October 8, Sen. Maggie Hassan (D-N.H.) wrote to Trump Mobile CEO Patrick O'Brien. Ars Technica reports that her letter cites the breach and the alleged "no team" reply. It also says Trump Mobile appears to lack FCC authorization for its international calling service and has not filed a required robocall mitigation plan, and that Liberty Mobile Wireless's robocall database filing is incomplete.

This is not the company's first exposure. Ars Technica notes that Trump Mobile previously confirmed a vendor had exposed customer data online, which SAN and SC Media connect to a website flaw found in May. SC Media also mentions an earlier leak by a group called EndZone. Biometric Update describes an unverified September claim by a different extortion group to hold data on about 4,000 users, including eSIM QR codes. The sources don't say whether the EndZone leak and the September claim are the same event, or whether either is connected to BYOD.

What Was Taken

SAN, PCMag, SC Media, Cybernews and Biometric Update all describe the same fields: first and last names, email addresses, phone numbers, home addresses and order or purchase details. BYOD also says the dump includes unspecified "telecom details."

The data includes no payment card numbers or government IDs. But names, phone numbers, home addresses and carrier account details together are exactly what an attacker needs for SIM-swap fraud, carrier social engineering and targeted phishing.

Why It Matters

MVNO trust chains are an attack surface. Trump Mobile depends on Liberty Mobile for much of its infrastructure. If BYOD's account is accurate, the attackers compromised the partner and then moved into the brand's own systems. Companies that hand operations to a white-label provider still carry the risk.

Telecom PII enables account takeover. Hassan's letter says Trump Mobile's customer authentication looks weak and its streamlined activation could make it easier for scammers to get US numbers. Combined with a leaked subscriber list, that weakness makes SIM swapping and number porting fraud more likely for the people exposed.

Executive exposure through personal accounts. The Trump Organization's CIO turning up in a consumer leak shows how security leaders' personal service accounts can leak data about high-value targets, whatever controls exist at their employer.

Incident response readiness. No one has verified the "no team to handle this" reply. Still, the lack of any public statement after a week of coverage, on top of earlier exposures, suggests the company has no working way to receive and act on breach notifications.

The Attack Technique

The only account of the intrusion path comes from BYOD. Biometric Update notes that no public forensic evidence yet backs up the entry point, the missing MFA or the claim of ongoing access.

What Organizations Should Do

  1. Require phishing-resistant MFA on every customer-data console, including internal lookup tools that partners and MVNO staff use. Use FIDO2 or passkeys rather than SMS where you can.
  2. Inventory and lock down your subdomains. Enumerate everything internet-facing, take down staging and admin hosts that don't need to be public, and put the rest behind identity-aware access.
  3. Treat outsourced operators' endpoints as part of your perimeter. Contractually require EDR, infostealer and RAT detection, and fast credential revocation for any third-party staff who can touch your customer systems.
  4. Bind sessions and watch for token reuse. Infostealers and RATs hijack live sessions, so use short session lifetimes, device-bound tokens, and alerts for dashboard logins from new hosts or odd locations.
  5. Add carrier-grade account protections after a leak. Turn on port-out PINs, number-lock and stronger identity checks for SIM changes on affected accounts, and tell customers about the SIM-swap risk.
  6. Keep a working disclosure channel. Run a monitored security contact (security.txt, a dedicated inbox) and an incident response retainer so extortion notices and researcher reports reach someone who can act.

Sources: My chat with a hacker who breached Trump Mobile | Trump Mobile doesn't seem to have FCC authorization for phone servi... | Ransomware group BYOD claims Trump Mobile data breach | Hackers: We Stole Data From 3,615 Trump Mobile Customers | Trump Mobile’s latest problem: Hackers just released customer infor... | Trump Mobile data breach exposes 3,615 users Cybernews | Hackers leak Trump Mobile customer data | Trump Mobile breach exposes customer data as earlier security ...