Trump Mobile data breach, Trump Mobile, Trump Mobile phishing
Trump Mobile licenses its name from the Trump Organization, whose own IT chief is named in the exposed file of customer records Kidfly182 / CC BY 4.0

A hacking group called BYOD claims to have dumped 3,615 Trump Mobile customer entries on a dark web leak site. The file reportedly contains names, email addresses, home addresses, phone numbers, and order records, Straight Arrow News reported on 5 October. Trump Mobile did not answer requests for comment.

Phishing is a scam in which criminals pose as a trusted firm to steal money or login codes. Order records let them pass as the phone company, which makes a fake harder to spot. Americans lost $470 million (£355 million) to scams that began with a text in 2024, the Federal Trade Commission (FTC) says.

What the Hackers Posted

Straight Arrow News reviewed the file and contacted the people listed, who confirmed the entries were accurate. PCMag found three people listed who said they had dealt with Trump Mobile before. Others listed said they had never been Trump Mobile customers. One man said he paid a $100 (£76) deposit for the gold T1 phone last year. He said he never received one. The message below, from a security account on X, drew over 7,800 likes.

BYOD claims it got in by planting malware on the device of a worker at Liberty Mobile Wireless LLC, which runs the network behind Trump Mobile. The group also says it can still reach a Trump Mobile dashboard holding customer account files. According to the hackers, Trump Mobile answered their warning with 'We have no team to handle this' and called anyone who hacks it a terrorist. No outside source has confirmed that exchange, and neither company answered The Register.

Why the Order Records Matter

The file shows plans people bought, such as a '30 Day Unlimited Talk Text Data' package. With that detail, a scammer can send a real-looking message about a failed renewal, a frozen line, or an unpaid bill. The FTC says fake account alerts are among the most common text scams. It advises forwarding suspect texts to 7726 and contacting a firm only through its official website or a known number.

The leak also includes Eric Brunnett, who runs IT at The Trump Organization. T1 Mobile LLC uses the Trump name under a licence from DTTM Operations, LLC. Brunnett said in an interview last year that his employer faced an 'unimaginable number of bad actors' trying to get in every day, Cybernews reported. None of the president's relatives appears in the data, Straight Arrow News has found.

A Pattern of Leaks Since May

This is not the first scare. In May, a researcher found a website flaw that exposed customer names and addresses, and Trump Mobile confirmed the problem. Jonathan Soma, who teaches at Columbia University, put the possible pre-orders in that data at about 27,224. Earlier reports put the $100 deposits at 590,000.

A second group, EndZone, claimed on 23 September to have breached Trump Mobile, nearly two weeks before BYOD went public. Security researcher Dominic Alvieri told The Register the EndZone dump 'appears to be the same original breach.' Whether the hackers still have access remains unclear. So does whether customers will hear from Trump Mobile about the leak.