The ransomware-as-a-service operation BYOD claims to have breached Trump Mobile and published a dataset reportedly containing 3,615 records with names, email addresses, phone numbers, home addresses and order details. Straight Arrow News confirmed some exposed information with affected individuals, although some denied being customers. The dataset reportedly includes Trump Organization vice president and chief information officer Eric Brunnett. Another criminal group, EndZone, published what researcher Dominic Alvieri described as apparently the same dataset a week earlier, leaving its provenance and the full scope of exposure uncertain.
BYOD alleges it infected an employee at Florida-based Liberty Mobile with an infostealer, used that access to reach Trump Mobile’s backend dashboard and retained access to its systems. The infection method, access path and claimed continuing access have not been independently established; the reports also do not establish password or payment-card exposure or ransomware encryption. Trump Mobile previously addressed a website vulnerability that reportedly exposed customer details, but no connection to this leak has been established. The exposed identity and order information could support targeted phishing and payment scams, making verification of third-party access, containment of any compromised sessions and notification of affected individuals key response priorities.

See attribution, scope, and your downstream exposure.
9 events from the most recent confirmed update back to the earliest known activity.
Straight Arrow News reported the incident after reviewing the leaked data and contacting listed individuals, several of whom confirmed their personal details. Some denied being Trump Mobile customers, so the verification did not establish the accuracy of every record.
Sen. Maggie Hassan sent Trump Mobile CEO Patrick O’Brien a letter citing customer-data exposures and questioning the company's authentication practices and robocall-mitigation filings. She also questioned whether Trump Mobile holds the required authorization for its advertised international calling services, raising national-security concerns.
BYOD told PCMag it compromised a Liberty Mobile employee with a remote access trojan, initially obtaining access limited to prepaid-number lookups. The report says BYOD then discovered exposed Trump Mobile subdomains and used them to bypass those restrictions and reach backend databases; this attack sequence has not been independently verified.
BYOD claimed responsibility for breaching Trump Mobile and published records containing names, contact information, home addresses, and order details, including information about Trump Organization CIO Eric Brunnett. The group also claimed continuing backend access and supplied a customer-information screenshot, but ongoing access and ransomware encryption were not confirmed.
The criminal group EndZone claimed to have breached Trump Mobile and published a dataset one week before BYOD's post. Researcher Dominic Alvieri assessed that the two disclosures appeared to involve the same original breach.
BYOD alleged that Trump Mobile responded to its breach warning by saying it had no team to handle the incident. This account of the company's response remains an attacker claim.
BYOD claimed it infected a Liberty Mobile employee with malware, described in The Register's account as an infostealer, and accessed Trump Mobile through the mobile virtual network operator. The infection method and access path have not been independently established.
The Register reported that the website vulnerability identified by Louis had been fixed. No date for the fix was provided.
A researcher using the name Louis said he discovered a Trump Mobile website vulnerability in May that allowed customer details to be retrieved with a simple POST request. The discovery preceded the EndZone and BYOD disclosures; the source does not specify the year.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourcescworld.com
Open sourcecyberveille.ch
Open sourcetheregister.com
Open sourcethecybersecguru.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.