Personal data of Trump Mobile customers has surfaced on a dark web platform, attributed to a breach by the ransomware group BYOD. The leaked information includes 3,615 records with names, email addresses, phone numbers, home addresses, and order details.
Details of the Breach
The incident was first reported by Straight Arrow News on October 5, 2026, after a thorough review of the leaked data and reaching out to some individuals listed. While several confirmed the accuracy of their information, others denied being customers, casting doubt on the authenticity of some entries.
Among those affected is Eric Brunnett, the vice president and chief information officer at the Trump Organization. His responsibilities include overseeing the organization’s technology and information security. However, no members of the Trump family were found in the dataset.
Claims of Malware Infection
A BYOD spokesperson revealed to Straight Arrow that the breach occurred through malware infection targeting an employee at Liberty Mobile, a Florida-based company associated with Trump Mobile. The brand, a subsidiary of T1 Mobile, operates under a license from the Trump Organization.
BYOD further claimed continued access to Trump Mobile’s backend dashboard, providing a screenshot as evidence. However, details regarding the malware type, infection method, and access pathways remain undisclosed. There is also no confirmed evidence of ransomware encrypting the company’s systems.
Potential Risks and Recommendations
The exposed contact and order information could facilitate phishing attacks, fake payment requests, or fraudulent customer support calls. Cybersecurity risks similar to this have been previously highlighted following other telecom data breaches.
Customers are advised to verify unexpected communications through official channels and refrain from sharing passwords or account details with unsolicited callers. It’s important to note that the breach report does not confirm the exposure of passwords or payment card numbers.
The enduring question is whether BYOD’s claimed backend access persists. Until confirmed, the full extent of the Trump Mobile breach remains unclear, along with any additional exposure risks.
To enhance security, organizations should consider integrating tools like TI Lookup into their SOC to reduce alert investigation times and improve response capabilities.
