Drooid Logo
Back to story perspectives

Full Breakdown

Trump Mobile Data Breach Exposes Thousands of Customers

By Drooid · · How we work

Breach Overview

In early October 2026 a ransomware-as-a-service group calling itself BYOD announced that it had accessed and published a file containing personal information for 3,615 Trump Mobile customers. The leaked records include names, email addresses, telephone numbers, home addresses and order details such as plan subscriptions and pre-order deposits. BYOD also asserted that it retained “live access to the dashboard” that powers the Trump Mobile website.

Background & Context

Trump Mobile is a cellular service launched in 2025 by Donald J. Trump Jr. and Eric Trump under the licensed Trump brand. The service is operated by T1 Mobile and relies on Liberty Mobile, a Florida-based mobile-virtual network operator, for network infrastructure. Earlier reporting highlighted supply-chain delays for the flagship “T1” gold-colored smartphone and questioned the company’s claim that devices were made in the United States. Security researchers had previously identified vulnerabilities in the company’s website, and the same flaws were cited as a possible vector for the current breach.

Data & Statistics

  • 3,615 customer records published on BYOD’s dark-web leak site.
  • Records contain first and last names, email addresses, phone numbers, home addresses, and order details.
  • The dataset includes personal information for Eric Brunnett, vice president and chief information officer of the Trump Organization.
  • A separate Straight Arrow investigation noted that no Trump family members appear in the leak.
  • Prior to the breach, 590,000 customers had paid a $100 pre-order deposit for the T1 phone, amounting to roughly $60 million in deposits, though many had not received the device.

Official Statements & Responses

Straight Arrow News reported that BYOD contacted Trump Mobile after the breach, receiving the reply, “We have no team to handle this,” and an additional statement labeling hackers as “terrorists.” BYOD later claimed the group still has access to the backend dashboard and supplied a screenshot showing customer data.

Trump Mobile has not provided a public comment to Straight Arrow News or other outlets. The company’s earlier response to the breach warning, as quoted by BYOD, was limited to the statement above.

On-the-Ground Reports

Multiple individuals contacted by Straight Arrow confirmed that the personal details in the leak matched their own records, validating the authenticity of at least part of the dataset. One customer who had paid a $100 deposit for the T1 phone reported never receiving the device. Several other contacted individuals denied ever being Trump Mobile customers, illustrating inconsistencies in the leaked list.

Conflicting Reports & Gaps

  • Customer status: While some contacted persons verified the data, others asserted they were not customers, leaving the exact proportion of genuine versus erroneous entries unclear.
  • Extent of ongoing access: BYOD claims continued backend access, but no independent verification has been published. The specific malware used to infect the Liberty Mobile employee and the method of lateral movement remain unconfirmed.
  • Impact on credentials: Reports have not established whether passwords, payment card numbers, or other authentication factors were exposed, limiting assessment of downstream fraud risk.

Verbatim Quotes

  • “We have no team to handle this,” — Trump Mobile
  • “They basically told us to go fuck ourselves,” — Trump Mobile. BYOD