Threat reportData BreachTL-2026-3297

BYOD Ransomware Group Claims Trump Mobile Customer Data Breach via Liberty Mobile Employee Malware Infection

mediumACTIVE

BYOD Ransomware Group Claims Trump Mobile Customer Data (TL-2026-3297) is a medium-severity data breach, first published 2026-10-10. It is attributed to BYOD with low confidence, affects T1 Mobile Trump Mobile (customer data / backend dashboard /, maps to 5 MITRE ATT&CK techniques (T1078, T1199, T1213), and is covered by 9 detection rules and 8 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
5MITRE ATT&CK
Actors
1BYOD
Detection rules
9SPL · KQL · Sigma
IOCs
8Indicators of compromise

Key facts for TL-2026-3297

Threat ID
TL-2026-3297
Severity
MEDIUM
Status
ACTIVE
Category
DATA_BREACH
First published
Last reviewed
Attribution
BYOD
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
telecoms, consumer-mobile, mvno
Target regions
North America
Detection rules
9
Indicators of compromise
8

Malware and tooling in BYOD Ransomware Group Claims Trump Mobile Customer Data

Malware and tooling: Dataleak, Unidentified 123 (Go Infostealer), remote access trojan (family unspecified)

How BYOD Ransomware Group Claims Trump Mobile Customer Data works

The newly emerged BYOD ransomware-as-a-service group claims it breached Trump Mobile (a T1 Mobile service) and posted 3,615 customer records on its dark web leak site. BYOD says it got in by infecting an employee of Liberty Mobile, the Florida-based MVNO behind Trump Mobile, with malware; the claim is unverified and neither company has confirmed it.

In early October 2026 the BYOD group, described by The Register as a new ransomware-as-a-service operation and the third organization listed on its data-leak site, published a dataset it attributes to Trump Mobile. The dataset reportedly holds 3,615 customer records: names, email addresses, phone numbers, home addresses and order details. Passwords and payment card numbers were not confirmed as exposed. Records reportedly include Eric Brunnett, the Trump Organization's technology/security chief, and a Florida-based Trump Organization lawyer; no Trump family members were found in the data. BYOD also supplied a screenshot of customer information as proof.

According to BYOD, initial access came from malware on the machine of an employee at Liberty Mobile, a Florida-based MVNO tied to Trump Mobile's network. Reporting disagrees on the malware class. The Register and SC World describe an infostealer; another outlet describes a remote access trojan. No family name, delivery vector or hash is published. BYOD says it then pivoted to exposed Trump Mobile subdomains and a backend dashboard, claims it retains live access, and says neither Liberty Mobile nor Trump Mobile used multi-factor authentication. The group also claims Trump Mobile replied to its breach notification with 'We have no team to handle this'. Trump Mobile did not respond to Straight Arrow News, Trump Organization and Liberty Mobile did not comment to The Register, and no source shows independent confirmation. No encryption of systems or ransom demand has been reported.

Context: a separate group, EndZone, claimed in September 2026 to have taken data on about 4,000 users, and The Register reports it leaked what appears to be the same original breach a week earlier; BYOD denies any formal tie to EndZone. Trump Mobile also had an earlier May 2026 incident in which a website flaw reportedly let a researcher pull pre-order customer data (about 27,000 records per IBTimes) with a simple POST request. Trump Mobile reportedly blamed a third-party platform for that incident. Defender takeaways: the exposed population faces phishing, fake payment requests and fraudulent support calls; MVNO and partner-employee endpoints are a trust-relationship path into brand-owner systems; and phishing-resistant MFA on backend dashboards, infostealer monitoring and subdomain exposure review are the relevant controls. All attack-method details come from the actor's own claims and have not been verified.

MITRE ATT&CK techniques used in TL-2026-3297

Initial Access

T1078 Valid Accounts; T1199 Trusted Relationship

Persistence

T1078 Valid Accounts

Collection

T1213 Data from Information Repositories

Command and Control

T1219 Remote Access Tools

Credential Access

T1555 Credentials from Password Stores

Affected products and versions in BYOD Ransomware Group Claims Trump Mobile Customer Data

  • T1 Mobile — Trump Mobile (customer data / backend dashboard / subdomains)
  • Liberty Mobile — MVNO employee endpoint and partner access to Trump Mobile systems

Remediation for BYOD Ransomware Group Claims Trump Mobile Customer Data

Immediate actions

  • Trump Mobile / T1 Mobile / Liberty Mobile: investigate the claimed breach, including the Liberty Mobile employee endpoint, and revoke sessions and credentials for the backend dashboard
  • Enforce MFA on all backend dashboards and partner/MVNO accounts, since BYOD claims neither company used it
  • Review and restrict exposed Trump Mobile subdomains
  • Customers: treat unsolicited messages and calls about orders, payments or support as suspect and verify through official channels

Workarounds

  • Affected customers should monitor for phishing, fake payment requests and fraudulent customer-support calls

Longer-term hardening

  • Deploy EDR and infostealer/credential-exposure monitoring on partner and MVNO employee endpoints
  • Apply least-privilege and network segmentation between MVNO partner access and brand-owner customer data
  • Establish an incident-response contact and process so breach notifications are triaged
  • Minimize retention of customer PII such as home addresses and order details

Timeline of BYOD Ransomware Group Claims Trump Mobile Customer Data

  • Trump Mobile launch announced (month-level date per The Register: June 2025).
  • Earlier, separate incident (month-level date): a Trump Mobile website flaw reportedly let a researcher extract pre-order customer data via a simple POST request; Trump Mobile reportedly blamed a third-party platform.
  • EndZone claimed (month-level date) to have taken data on about 4,000 Trump Mobile users; unverified. The Register reports it appears to be the same original breach, and BYOD denies a formal tie.
  • Straight Arrow News and Android Authority report that BYOD posted 3,615 Trump Mobile customer records on its dark web leak site and claims a Liberty Mobile employee malware infection as initial access.
  • The Register and Cyber Security News report BYOD is a new RaaS operation. BYOD claims no MFA at Liberty Mobile or Trump Mobile, retained live dashboard access, and a 'We have no team to handle this' reply from Trump Mobile. Trump Organization and Liberty Mobile gave no comment.
  • IBTimes UK reports Trump Mobile has not publicly confirmed the BYOD breach and that no encryption or ransom demand is evident.

Sources cited for BYOD Ransomware Group Claims Trump Mobile Customer Data

Detection coverage for TL-2026-3297

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3297 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
8 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats