Skip to content
Trump Mobile data breach, BYOD gang leaks 3,615 customers' records

Trump Mobile data breach, BYOD gang leaks 3,615 customers' records

Pasqualepillitteri.It • October 6, 2026

The criminal group BYOD has posted the data of 3,615 Trump Mobile customers (name, email, phone number, address and order details) on its dark web site, as Straight Arrow News (SAN) reported on October 5, 2026. The list also includes the executive who handles IT and security at the Trump Organization, the family company that licenses its brand to the carrier.

Almost everything else in the story, however, runs through the attackers' voice. Trump Mobile has, in fact, not responded to SAN's request for and has not publicly acknowledged the incident. The published data exists and in part checks out, while how the intrusion happened and an alleged access that is still open remain, for now, BYOD's version of events.

What the Trump Mobile leak contains

The file holds 3,615 records. Each entry lists first and last name, email address, phone number, address and order details. Neither credit card numbers nor passwords appear in the sources consulted.

The most concrete check came from SAN, which phoned some of the people listed. Several confirmed their details were correct; some of them, though, denied being Trump Mobile customers before hanging up. No source explains the contradiction. Our own hypothesis, unconfirmed, is that the database also includes the contacts of people who started an order without completing it or joined a waitlist.

Among the 3,615 names is the vice president and Chief Information Officer of the Trump Organization, described by SAN as the person who oversees all of the organization's IT and cybersecurity. We are not printing the name (the file is a dump of personal data and citing it adds nothing to the story). Being on the list implies no wrongdoing. His details are, in fact, in the file, and International Cyber Digest put them at the top of its own post.

How BYOD says it got in

According to a BYOD spokesperson, entry came through an employee of Liberty Mobile, a Florida company whose link to Trump Mobile none of the sources explains. The employee was reportedly infected with an infostealer (malware that copies the passwords saved in the browser and the session cookies, the small files that keep a person "logged in" after signing in). From there the gang allegedly reached Trump Mobile's systems.

BYOD described the same sequence of events to International Cyber Digest , the X account that amplified the case, adding that neither company used multi-factor authentication (MFA, the second check after the password, such as a code generated by an app or a physical key). If that is true, the stolen password was enough by itself. The more access a company hands to its partners, the more its security becomes that of its most careless partner.

Credential theft through infostealers has long been the most common way in. The CRIF Observatory counted 2.5 billion records on the dark web in the first half of 2026, with Italy third in the world for accounts stolen by this very kind of malware.

The gang also claims it still has access to Trump Mobile's backend dashboard (the panel the company uses to manage its customers) and sent SAN a screenshot showing a customer's personal data. A screenshot, by itself, proves neither the date nor the persistence of the access. It is, however, the kind of material journalists ask for to work out whether a group really holds the panel or only a file.

Trump Mobile's silence

According to BYOD's account, after the breach notice Trump Mobile allegedly replied "We have no team to handle this" and called anyone who attacks it a "terrorist". The quote comes from the gang, not from a company statement; no independent source has confirmed it. Trump Mobile, for its part, did not respond to SAN either.

If the were authentic, it would describe a company that holds the data of thousands of people with no point of for incidents. That would be hard to square with the obligation, in many US states, to notify affected customers without unreasonable delay. All told, for now, there is no confirmation and no denial.

‼️ BREAKING: Trump Mobile customers have had their personal data leaked by ransomware gang BYOD. The dump covers 3,615 people and includes names, emails, phone numbers, addresses and order details. The gang says the company answered news of the breach with "We have no team to handle this." The leak includes the Trump Organization's own CIO, who oversees its information security. People listed in the data confirmed their details are accurate and BYOD claims it still has access to Trump Mobile's backend, Straight Arrow News reports. — International Cyber Digest (@IntCyberDigest) October 5, 2026

‼️ BREAKING: Trump Mobile customers have had their personal data leaked by ransomware gang BYOD. The dump covers 3,615 people and includes names, emails, phone numbers, addresses and order details. The gang says the company answered news of the breach with "We have no team to handle this." The leak includes the Trump Organization's own CIO, who oversees its information security. People listed in the data confirmed their details are accurate and BYOD claims it still has access to Trump Mobile's backend, Straight Arrow News reports.

Is it really a ransomware attack?

The Trump Mobile case looks more like data theft with publication than a classic ransomware attack, because the sources consulted mention neither encrypted systems nor a ransom demand. BYOD stole data and put it online; the ransomware group label describes its trade, which runs through a publication site (a leak site, the page where gangs display stolen data) used to pressure victims. The ransomware.live tracker lists it as an emerging group and gives September 29 as the estimated date of the attack.

The pattern (theft, publication, no encryption) is now common. The IAmNotAVillain group opened a leak site on Tor to demand ransom from individual Revolut customers , while ShinyHunters claimed the attack on FBIjobs.gov , saying it has data on nearly every agent. Even gangs that formed only recently often have short lives; the operation against KillSec , with three arrests and 110 terabytes recovered, is a precedent.

The second incident in under five months

Two incidents, two mechanisms. In May an online exposure, in late September an intrusion that came (again according to BYOD) through a supplier. We do not know whether the 3,615 records are a subset of the roughly 30,000 from May, because no source says. An exposure with no real attack remains, in any case, the easiest to prevent, as the case of the Elasticsearch cluster left open by Nextcloud with 367,000 records shows.

Why a carrier's data is worth more than an email list

Phone number, email, address and order in the same record make the ideal kit for two scams. The first is targeted phishing, with messages that cite a real order and a real address. SAN recalls the phone delivery delays reported in May; a text message posing as a shipping update thus has a pretext ready-made.

The second is a SIM swap (the procedure in which a fraudster convinces the carrier to move the number to a SIM the fraudster controls), which is used to intercept verification codes sent by SMS. Someone who has a person's exact phone number and address starts with an advantage when calling a carrier's support line.

What to do if you are a Trump Mobile customer

The concrete risk lies in the combination of tailored phishing and number theft, since nothing in the file points to a charge on the card. The useful moves are few.

Change the Trump Mobile account password and that of any other service where the same one was used, then turn on MFA with an authenticator app instead of SMS codes, which a SIM swap bypasses.

Distrust emails, texts and phone calls that cite the order or the address, because whoever is writing now has those exact details.

Request a credit freeze from the US credit bureaus, free by law, if you live in the United States.

Call the carrier to set a PIN or passphrase on number transfers.

Why it matters outside the United States too

Trump Mobile is a US carrier and the sources do not mention European customers. The mechanism, though, applies everywhere. A partner's employee infected with commercial malware and the lack of a second factor are enough, again according to BYOD, to open up a company's backend. In Europe a similar incident would require the data controller to notify the supervisory authority within 72 hours of discovery (Article 33 of the GDPR) and, if the risk is high, to inform the people affected.

The theme appeared on a different scale with the Danish CPR registry , where unauthorized access exposed the names, addresses and ID numbers of 8.8 million people. A small company has just one check to run today. Verify that every administrative login, starting with those of suppliers, requires MFA.

Frequently asked questions (FAQ)

1. Who is BYOD, and why does the name cause confusion?

BYOD is the name under which the gang appears in ransomware group trackers, where it is listed as emerging; SAN describes it as newly formed. The acronym matches the corporate term Bring Your Own Device (the practice of using personal devices for work), which has nothing to do with this case. No other victims of the group appear in the sources read.

2. How do I know if my data is in the leak?

The sources consulted point to no public service for checking. Services such as Have I Been Pwned add a dataset only after obtaining and vetting it, so the absence of a result today is no guarantee. It is wise to assume exposure if you have a Trump Mobile account.

3. Does the leak contain passwords or card numbers?

In the sources read, the file contains name, email, phone number, address and order details, with no passwords or card numbers. In May, according to one of the two creators cited by TechCrunch, the exposure covered everything "except the credit card number". Doubt remains what BYOD says it can still read from the backend.

4. Why doesn't the risk end when I change my password?

An infostealer also copies session cookies, the files that prove to a website that sign-in has already happened. With a valid cookie the attacker can pose as an already authenticated user, sometimes even where MFA is on. After an infection, then, you close open sessions and clean the computer, on top of changing passwords.

What remains to be verified

Verified and unverified. The file with 3,615 records exists and some of the people listed confirm it is accurate. The entry through Liberty Mobile, the absence of MFA, the still-open backend access and the quote attributed to Trump Mobile, however, come only from BYOD; no independent source has confirmed them.

The step that would change the picture is a statement from Trump Mobile, confirming or denying. If one arrives, or if BYOD publishes more material, we will update this page. In the meantime, anyone with an account can already do the two most useful things, namely change the password and turn on the second factor.

Sources and further reading

Straight Arrow News, the October 5, 2026 case

Security Online, the infostealer dynamic and the absence of MFA

TechCrunch, the May 2026 data exposure

ransomware.live, the victim's entry