Trump Mobile Customer Data Stolen in Hacker Breach

A hacking group known as BYOD claims to have exfiltrated the personal data of 3,615 Trump Mobile customers after compromising an employee at a Florida-based mobile virtual network operator, according to PCMag.

The Malware Infection and Data Exfiltration

The breach began when the cybercrime collective installed a Remote Access Trojan on the device of a worker at Liberty Mobile. Liberty Mobile is a Florida-based MVNO that provides the network infrastructure for Trump Mobile. According to details shared by BYOD in an email to PCMag, the initial compromise granted limited privileges restricted to prepaid number lookups. From there, the gang pivoted to exposed subdomains belonging to Trump Mobile to harvest the customer database.

The stolen records contained names, phone numbers, email addresses, and physical addresses. Straight Arrow News initially broke the news of the alleged breach after the group published the file on its dark web site last week. Three affected individuals independently confirmed to PCMag that the leaked information accurately matched their historical interactions with Trump Mobile. One customer even found that the file correctly noted the cancellation of their “30 Day Unlimited Talk Text Data” plan.

Response and Past Vulnerabilities

When informed of the security failure by hackers, Trump Mobile representatives allegedly replied via email that they had “no team to handle this” and characterized anyone who hacks them as a terrorist. Neither Trump Mobile nor Liberty Mobile responded to subsequent press requests for comment regarding the incident.

This is not the first time security flaws have plagued the brand. In May, two independent researchers identified an exploitable software vulnerability on TrumpMobile.com that exposed customer names, phone numbers, and physical addresses. While Trump Mobile patched that specific issue at the time and reported finding no evidence of active compromise, security analysts have speculated that BYOD may have exploited similar underlying exposures to execute this latest exfiltration.

Manchester airport group
Photo: bbc.co.uk

Intersecting Claims From Competing Hacking Factions

Complicating the timeline of the attack, another hacking collective named Endzone claimed last month to have stolen data from 4,000 Trump Mobile users. When questioned about a potential connection, a BYOD representative stated that there was no formal affiliation between the two groups, though acknowledging that an individual in their circle maintains casual ties with members of Endzone.

Meanwhile, the operational security posture of the platform remains under scrutiny. One customer whose information appeared in the leaked file noted that she never successfully completed a subscription or preorder for the delayed Trump-branded phone. Her email and phone number were nevertheless retained in company systems following prior customer service inquiries, illustrating how minimal engagement points can feed into broader database vulnerabilities.

Photo of author

Sophie Lin - Technology Editor

Sophie is a tech innovator and acclaimed tech writer recognized by the Online News Association. She translates the fast-paced world of technology, AI, and digital trends into compelling stories for readers of all backgrounds.

Bedok pork stall owner says raw meat on floor was rinsed with water