Trump Mobile Customers Face Phishing Risk After Hackers Post 3,615 Names, Addresses and Phone Numbers Online
BYOD says it got in through a partner's worker, but the plan details it leaked make fake texts look genuine

A hacking group called BYOD claims to have dumped 3,615 Trump Mobile customer entries on a dark web leak site. The file reportedly contains names, email addresses, home addresses, phone numbers, and order records, Straight Arrow News reported on 5 October. Trump Mobile did not answer requests for comment.
Phishing is a scam in which criminals pose as a trusted firm to steal money or login codes. Order records let them pass as the phone company, which makes a fake harder to spot. Americans lost $470 million (£355 million) to scams that began with a text in 2024, the Federal Trade Commission (FTC) says.
What the Hackers Posted
Straight Arrow News reviewed the file and contacted the people listed, who confirmed the entries were accurate. PCMag found three people listed who said they had dealt with Trump Mobile before. Others listed said they had never been Trump Mobile customers. One man said he paid a $100 (£76) deposit for the gold T1 phone last year. He said he never received one. The message below, from a security account on X, drew over 7,800 likes.
‼️ BREAKING: Trump Mobile customers have had their personal data leaked by ransomware gang BYOD. The dump covers 3,615 people and includes names, emails, phone numbers, home addresses and order details.
— International Cyber Digest (@IntCyberDigest) October 5, 2026
The gang says the company answered news of the breach with "We have no team… pic.twitter.com/KmeVbGi4ss
BYOD claims it got in by planting malware on the device of a worker at Liberty Mobile Wireless LLC, which runs the network behind Trump Mobile. The group also says it can still reach a Trump Mobile dashboard holding customer account files. According to the hackers, Trump Mobile answered their warning with 'We have no team to handle this' and called anyone who hacks it a terrorist. No outside source has confirmed that exchange, and neither company answered The Register.
Why the Order Records Matter
The file shows plans people bought, such as a '30 Day Unlimited Talk Text Data' package. With that detail, a scammer can send a real-looking message about a failed renewal, a frozen line, or an unpaid bill. The FTC says fake account alerts are among the most common text scams. It advises forwarding suspect texts to 7726 and contacting a firm only through its official website or a known number.
The leak also includes Eric Brunnett, who runs IT at The Trump Organization. T1 Mobile LLC uses the Trump name under a licence from DTTM Operations, LLC. Brunnett said in an interview last year that his employer faced an 'unimaginable number of bad actors' trying to get in every day, Cybernews reported. None of the president's relatives appears in the data, Straight Arrow News has found.
A Pattern of Leaks Since May
This is not the first scare. In May, a researcher found a website flaw that exposed customer names and addresses, and Trump Mobile confirmed the problem. Jonathan Soma, who teaches at Columbia University, put the possible pre-orders in that data at about 27,224. Earlier reports put the $100 deposits at 590,000.
A second group, EndZone, claimed on 23 September to have breached Trump Mobile, nearly two weeks before BYOD went public. Security researcher Dominic Alvieri told The Register the EndZone dump 'appears to be the same original breach.' Whether the hackers still have access remains unclear. So does whether customers will hear from Trump Mobile about the leak.
© Copyright IBTimes 2026. All rights reserved.

