Cyber Security News

Hacker Group Claims to Have Stolen Trump Mobile Customers’ Personal Data

Trump Mobile customers’ personal data has appeared on a dark web leak site after a ransomware group called BYOD claimed it breached the company. The published file reportedly contains 3,615 records, including names, email addresses, phone numbers, home addresses, and order details.

Straight Arrow News reported the incident on October 5, 2026, after reviewing the leaked data and contacting people listed in it. Several individuals confirmed their details were accurate, although some denied being customers. This supports the authenticity of some records, but does not confirm every entry.

The exposed information includes Eric Brunnett, vice president and chief information officer at the Trump Organization. His role covers the organization’s technology and information security. Straight Arrow found no Trump family members in the dataset.

Claimed Access Through Malware

A BYOD representative told Straight Arrow that the group gained access after infecting an employee at Florida-based Liberty Mobile with malware. Trump Mobile is owned by T1 Mobile and uses branding licensed from the Trump Organization.

BYOD also claimed it still had access to Trump Mobile’s backend dashboard and supplied a screenshot showing customer information. The malware family, infection method, and access path have not been publicly established. The report also provides no confirmed evidence that ransomware encrypted company systems.

The group alleged Trump Mobile responded to its breach warning with, “We have no team to handle this.” That account remains the attackers’ claim. Trump Mobile had not responded to Straight Arrow’s request for comment when it published its report.

Exposed contact and order details could help criminals craft convincing phishing messages, fake payment requests or calls posing as customer support. Cybersecurity News previously covered similar risks following the Odido telecom data breach.

Customers should verify unexpected messages through official channels and avoid sharing passwords or account codes with callers. The report does not establish that passwords or payment card numbers were exposed.

The key unanswered question is whether the claimed backend access remains active. Until that is verified, the full scope of the alleged Trump Mobile data breach remains uncertain, including any further exposure.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access

ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote…

6 minutes ago

FBI Removes Accenture Contractor After Unpatched PeopleSoft Flaw Exposes Thousands of Employees

The FBI removed an Accenture contractor on October 5, 2026, after a missed security patch…

6 minutes ago

Google Adds 6 Advanced Protection Features to Android 17 Against Sophisticated Attacks

Google has detailed six Advanced Protection enhancements for Android 17, targeting sophisticated attacks, scams and…

35 minutes ago

Atlassian Patches Critical Vulnerabilities in Jira, Confluence, Bitbucket, and Five More Products

Atlassian has disclosed a critical arbitrary file access vulnerability affecting eight products, including Jira, Confluence,…

55 minutes ago

Top 10 Best SAST Tools in 2026 [Ranked & Scored]

The AI-code flood made one truth undeniable: static analysis only matters if developers fix what…

1 hour ago

Top 10 Best Just-in-Time (JIT) Access Tools in 2026 [Ranked & Scored]

Credentials that always work are credentials worth stealing which is why mitigating how attackers exploit…

2 hours ago