← DOOMRADAR
cyber · First tracked by DoomRadar:
42DOOM SCORE

Hackers claim Trump Mobile customer data was leaked

A group called BYOD claims it accessed Trump Mobile through its mobile-network provider and published data on 3,615 customers. The reported dump includes contact, address and order details, but the company’s response and the full scope of access remain unclear.

By DoomRadar · Published on DoomRadar . Updated .

Based on two sources with available article excerpts. Source-linked claims are not independent confirmation.

What happened

BYOD, described by The Register as a new ransomware-as-a-service operation, claimed it stole and published personal information linked to 3,615 Trump Mobile customers. The claim concerns the Trump-branded wireless business, not the personal accounts of Donald Trump or his family. [1][2]

References for this detail (2)

The reported data includes names, email addresses, phone numbers, home addresses and order details. That combination can link a customer’s identity and contact information with a commercial relationship, although the full authenticity and completeness of the dump are not established here. [1][2]

References for this detail (2)

The Register said the hackers claimed they reached Trump Mobile through a Liberty Mobile employee infected with an infostealer, then accessed the service through its mobile virtual network operator arrangement. This account is attributed to the attackers and is not independently confirmed in the excerpts. [2]

References for this detail (1)

The attackers reportedly said they still had access to Trump Mobile’s systems and alleged that neither wireless provider used multi-factor authentication. Those are claims by the hacking group; the excerpts do not establish whether access continued or whether the security allegation was verified. [2]

References for this detail (1)

The reported incident also includes a dispute about service delivery: one customer told Straight Arrow News that a $100 pre-order deposit paid for the T1 phone had not resulted in receiving the device. That account is separate from proof about the data leak itself. [2]

References for this detail (1)

Context from the sources

The Register noted that a security researcher had reported a separate Trump Mobile website vulnerability in May and said it had since been plugged. That earlier issue provides security context but does not establish that it caused the newly claimed incident. [2]

Explore the sources and reporting timeline

2 source links · 2 domains

These counts describe the references, not independent confirmations. Different outlets can repeat the same original report.

Source timeline

Oldest to newest among the available source dates, not a chronology of the incident. Article publication dates come from the source; other recorded dates may reflect when a link was found.

  1. Article published: Oct 6, 2026, 2:09 PM UTC[1] Trump Mobile Leak Exposes Its Own Security Chief as Hackers Claim Company Had 'No Team' To Handle Breachibtimes.co.ukReferenced for: detail 1, detail 2
  2. Article published: Oct 6, 2026, 5:32 PM UTC[2] Trump Mobile customers' data dumped - and some never even received their gold devicetheregister.comReferenced for: detail 1, detail 2, detail 3, detail 4, detail 5

What this could mean for you

Digital services

Affected customers may receive more convincing phishing or impersonation attempts.

Exposed contact, address and order details can help attackers tailor messages around a real customer relationship.

Reported basis: [1][2] · The possible effect is interpretation.

Depends on: The claimed records must be authentic and accessible to other people.

Safety

Some customers could face unwanted contact or privacy concerns linked to exposed home addresses.

The reported dataset includes residential addresses alongside names and phone numbers.

Reported basis: [1][2] · The possible effect is interpretation.

Depends on: The address records are genuine and remain publicly accessible.

Possible consequences, not a forecast. Their relevance depends on your location and the conditions above.

For your country

Choose a country to check how this event could affect you.

What changes the outlook

Risk increases if…

Further publication or redistribution of authentic customer records would increase exposure.

Evidence that attackers retain access to Trump Mobile systems would raise the risk beyond the reported data dump.

Pressure eases if…

Independent confirmation that the records are fabricated or substantially incomplete would reduce the immediate privacy concern.

Effective containment and customer notification would limit further misuse if the breach claim is genuine.

Still unclear

Whether the leaked records are authentic and complete has not been independently established in the excerpts.

The company’s containment measures, customer notification and the attackers’ current access are unclear.

Market implications

Market impact

Loading market analysis...
Sources (2)

References for the reported details. Separate links do not necessarily mean independent confirmation.

AI-assisted analysis · . Based on linked headlines and available excerpts. Methodology · Report an error.