# BYOD Ransomware Group Claims Trump Mobile Customer Data Breach via Liberty Mobile Employee Malware Infection

> The newly emerged BYOD ransomware-as-a-service group claims it breached Trump Mobile (a T1 Mobile service) and posted 3,615 customer records on its dark web leak site. BYOD says it got in by infecting an employee of Liberty Mobile, the Florida-based MVNO behind Trump Mobile, with malware; the claim is unverified and neither company has confirmed it.

- **Published:** 2026-10-10T18:43:04Z
- **Last reviewed:** 2026-10-10T18:43:04Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3297
- **ID:** TL-2026-3297
- **Severity:** MEDIUM
- **Category:** DATA_BREACH
- **Status:** ACTIVE
- **Actor:** BYOD
- **Detections:** 9 · **IOCs:** 8 (full data via the Threadlinqs MCP server — Purple tier)

## Description

In early October 2026 the BYOD group, described by The Register as a new ransomware-as-a-service operation and the third organization listed on its data-leak site, published a dataset it attributes to Trump Mobile. The dataset reportedly holds 3,615 customer records: names, email addresses, phone numbers, home addresses and order details. Passwords and payment card numbers were not confirmed as exposed. Records reportedly include Eric Brunnett, the Trump Organization's technology/security chief, and a Florida-based Trump Organization lawyer; no Trump family members were found in the data. BYOD also supplied a screenshot of customer information as proof.

According to BYOD, initial access came from malware on the machine of an employee at Liberty Mobile, a Florida-based MVNO tied to Trump Mobile's network. Reporting disagrees on the malware class. The Register and SC World describe an infostealer; another outlet describes a remote access trojan. No family name, delivery vector or hash is published. BYOD says it then pivoted to exposed Trump Mobile subdomains and a backend dashboard, claims it retains live access, and says neither Liberty Mobile nor Trump Mobile used multi-factor authentication. The group also claims Trump Mobile replied to its breach notification with 'We have no team to handle this'. Trump Mobile did not respond to Straight Arrow News, Trump Organization and Liberty Mobile did not comment to The Register, and no source shows independent confirmation. No encryption of systems or ransom demand has been reported.

Context: a separate group, EndZone, claimed in September 2026 to have taken data on about 4,000 users, and The Register reports it leaked what appears to be the same original breach a week earlier; BYOD denies any formal tie to EndZone. Trump Mobile also had an earlier May 2026 incident in which a website flaw reportedly let a researcher pull pre-order customer data (about 27,000 records per IBTimes) with a simple POST request. Trump Mobile reportedly blamed a third-party platform for that incident. Defender takeaways: the exposed population faces phishing, fake payment requests and fraudulent support calls; MVNO and partner-employee endpoints are a trust-relationship path into brand-owner systems; and phishing-resistant MFA on backend dashboards, infostealer monitoring and subdomain exposure review are the relevant controls. All attack-method details come from the actor's own claims and have not been verified.

## MITRE ATT&CK

- T1199 Trusted Relationship
- T1078 Valid Accounts
- T1555 Credentials from Password Stores
- T1219 Remote Access Tools
- T1078 Valid Accounts
- T1213 Data from Information Repositories

## Sources

- [Hacker Group Claims to Have Stolen Trump Mobile Customers' Personal Data](https://cybersecuritynews.com/trump-mobile-data-breach/)
- [The Register: Trump Mobile data breach (BYOD ransomware-as-a-service claim)](https://www.theregister.com/a/5301433)
- [Straight Arrow News: Trump Mobile's latest problem: Hackers just released customer information](https://san.com/cc/trump-mobiles-latest-problem-hackers-just-released-customer-information/)
- [Android Authority: Trump Mobile subscriber data leak](https://androidauthority.com/trump-mobile-subscriber-data-leak-3719958)
- [IBTimes UK: Trump Mobile Hackers Claim the Company Admitted It Had 'No Team' To Handle the Data Breach](https://www.ibtimes.co.uk/hackers-claim-trump-mobile-data-breach-3615-customers-1824112)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3297
