Trump Mobile Hack? 3,615 Records Hit Dark Web as Hackers Claim They Still Have Access

The breach exposes names, contact details, and specific plan histories, catching even unfinished sign-ups in the net

Trump Mobile Data Breach BYOD Hack
A freshly emerged hacker collective known as 'BYOD' has leaked the personal records of 3,615 Trump Mobile customers online after infiltrating a network employee with malware X / Trump Mobile

A ransomware group claims it has leaked a dataset containing personal information from 3,615 records linked to Trump Mobile, while also claiming it still has 'live access' to a company dashboard.

The suspected cyberattack was initially reported by Straight Arrow News, with a collective known as BYOD stepping forward to claim responsibility. Last week, the group published a file on its dark web site purportedly containing names, phone numbers, email addresses, home addresses and order information.

3,615 Records Surface Online

According to BYOD's website, the group claims Trump Mobile was notified about the intrusion and allegedly replied that it had no team to manage the situation, while saying anyone who breached its networks was a terrorist. The alleged exchange has not been independently authenticated.

BYOD has also claimed it still has 'live access to the dashboard' on TrumpMobile.com. That claim has not been independently verified.

Three individuals listed in the dataset confirmed to PCMag that information attributed to them was accurate. Reporters contacted them using personal details contained in the files, including full names, phone numbers, email addresses and home addresses.

However, the 3,615 records should not necessarily be treated as 3,615 confirmed Trump Mobile customers. One person whose details appeared in the dataset told reporters she had never successfully registered for the service or placed a reservation for the company's much-delayed branded handset.

Hackers Claim Employee Was Targeted

BYOD claims it gained access through an employee at Liberty Mobile, a Florida-based mobile virtual network operator that provides the network service for Trump Mobile.

The group told PCMag that it 'ratted a Liberty Mobile employee', referring to the use of a Remote Access Trojan, or RAT, which can allow attackers to remotely control an infected computer.

According to BYOD, the initial malware infection provided limited access, allowing the attackers to look up prepaid numbers. BYOD claims it then pivoted to subdomains associated with Trump Mobile and used that access to exfiltrate data.

In an email to PCMag, BYOD said the initial infection gave it 'no permissions except to look up prepaid numbers, so we pivoted to subdomains, which Trump Mobile was exposed, and decided to exfil that'.

The collective further claimed, 'We only stole 3,615 customers due to the fact that's all they have using their MVNO (different from the prepaid phone orders, these are people using the carrier)', while maintaining that it still has 'live access to the dashboard' on TrumpMobile.com.

The alleged attack route has not been independently verified.

Leaked Records Put Customer Data Under Scrutiny

BYOD claims the stolen records belong to people who are currently or were previously using the MVNO as their cellular network.

However, one person identified in the dataset said she never became a Trump Mobile customer. She told reporters that she had previously shared her email address and phone number with the company, which could explain why her information appeared in the leaked database.

'They wouldn't sell me the phone because my email was already in their system,' the buyer stated, adding that the company's support team 'sucked.'

A Trump Mobile support representative also used the same phone number to contact her, suggesting the company had previously retained her details.

The case highlights why the number of records in the leaked dataset should not automatically be equated with the number of confirmed Trump Mobile customers.

Trump Mobile Faces Fresh Security Questions

Neither Trump Mobile nor Liberty Mobile has issued a public comment on the latest incident.

The alleged breach follows a separate security exposure reported in May, when two content creators flagged a vulnerability on TrumpMobile.com that risked exposing names, telephone numbers and addresses. The company later patched the weakness while denying that its systems had been compromised.

There is currently no evidence establishing that the May vulnerability and the latest incident are connected. A cybersecurity account on X has speculated that BYOD could have exploited the same weakness.

The latest incident also comes after another collective, Endzone, claimed in September that it had stolen records belonging to around 4,000 users. BYOD has denied any affiliation with the group.

A BYOD spokesperson told reporters, 'No, we have no affiliation; a member from our group just knows a few people behind Endzone, so there could've been a hiccup regarding Trump Mobile & Eteam, although we have published both first... However, we wish them the best, of course.'