Trump Mobile Allegedly Tells Ransomware Group 'We Have No Team To Handle This' After Dark Web Breach
A ransomware gang claims to have leaked 3,615 Trump Mobile customers' personal data, including the Trump Organization CIO, after allegedly infecting a partner company with malware

A ransomware group called BYOD claims to have breached Trump Mobile and published a file reportedly containing personal details from 3,615 records on a dark web leak site on 5 October 2026.
The exposed records reportedly include names, email addresses, phone numbers, home addresses and order details, with the Trump Organization's own chief information officer among those listed.
To recall, this is not the first security scare for the politically branded MVNO. In May 2026, two YouTubers flagged an exploitable flaw on TrumpMobile.com that could have leaked similar customer information, though the company said at the time it found no evidence its systems were compromised.
Alleged Malware Infection and Disputed Response
According to Straight Arrow News, which first reported the incident, a representative for BYOD told the outlet the group gained access after infecting an employee at Florida-based Liberty Mobile with malware. Liberty Mobile is known to power Trump Mobile, which is owned by T1 Mobile and uses branding licensed from the Trump Organization.
The attackers claimed they installed a Remote Access Trojan on the target's device, then pivoted to exposed Trump Mobile subdomains to exfiltrate customer data.
BYOD also alleged it retains 'live access' to a Trump Mobile backend dashboard and supplied a screenshot showing customer information, though the malware family, infection method and access path have not been publicly established.

BYOD's account of Trump Mobile's response when warned about the breach has also drawn attention. 'Trump Mobile was informed they had been breached, they then replied with "We have no team to handle this" and that anyone who hacks them are a terrorist,' BYOD wrote on its dark web site.
Trump Mobile did not immediately respond to requests for comment from Straight Arrow or PCMag. It can be recalled that another hacking group, Endzone, claimed last month to have stolen data from 4,000 Trump Mobile users.
A BYOD representative denied affiliation, saying a member of their group 'just knows a few people behind Endzone, so there could've been a hiccup regarding Trump Mobile & Eteam.'
Verified Records and Phishing Risks
PCMag verified parts of the leak by using the exposed data to contact three affected customers, who confirmed they had interacted with Trump Mobile in the past. One customer was surprised the file accurately showed they had canceled their service for the '30 Day Unlimited Talk Text Data' plan.
Another said she never successfully signed up, though she had given the company her email and phone number.
Straight Arrow found no Trump family members in the dataset, but the records did include Eric Brunnett, vice president and chief information officer at the Trump Organization, whose role covers the organisation's technology and information security.
Several other individuals confirmed their details were accurate, although some denied being customers, supporting the authenticity of some records but not confirming every entry.
Cybersecurity experts warn that exposed contact and order details could help criminals craft convincing phishing messages, fake payment requests or calls posing as customer support.
The report does not establish that passwords or payment card numbers were exposed, but customers should verify unexpected messages through official channels and avoid sharing passwords or account codes with callers.
The key unanswered question is whether the claimed backend access remains active. Until that is verified, the full scope of the alleged Trump Mobile data breach remains uncertain, including any further exposure.
© Copyright IBTimes 2026. All rights reserved.

