Trump Mobile Data Breach: What Happened and Who's Affected

A leak group calling itself BYOD says it exposed names, emails, phone numbers and home addresses tied to 3,615 Trump Mobile customers. Trump Mobile has not confirmed the breach.

The Trump Mobile logo in gold lettering
The Trump Mobile brand logo. Image: Trump Mobile.

A hacker group calling itself BYOD says it has leaked personal data belonging to 3,615 Trump Mobile customers, including names, email addresses, phone numbers, home addresses and order details. The data was posted to BYOD's dark-web leak site and first reported by Straight Arrow News on October 5, 2026, with The Register and Cybernews following up the next day. As of this writing, neither Trump Mobile nor its parent, the Trump Organization, has issued a public statement confirming or denying the breach.

What happened

BYOD, a relatively new data-leak and ransomware-style group, published a dataset on its leak site claiming it belonged to Trump Mobile, the wireless brand that operates as a mobile virtual network operator (MVNO) under license from the Trump Organization. According to Cybernews, which reviewed samples of the data, the leak site listing went up in late September, with a ransomware-tracking account flagging the Trump Mobile entry around September 29, 2026, before wider press coverage followed in early October. Cybernews said Trump Mobile is only the third organization to appear on BYOD's leak site, suggesting the group is newly active.

Straight Arrow News, which first reported the story, said it contacted several people named in the dataset and that some confirmed the personal details attached to their names and addresses were accurate, lending credibility to at least part of BYOD's claim. Others contacted said they did not recognize themselves as Trump Mobile customers, a detail both The Register and Cybernews noted without resolving.

What data was exposed

Multiple outlets that reviewed the leaked sample describe a consistent set of fields. Importantly, none of the reporting to date has identified passwords, card numbers, banking details or Social Security numbers inside this particular dataset.

Reportedly exposedReportedly not exposed
Full namesPasswords or login credentials
Email addressesCredit or debit card numbers
Phone numbersBank account details
Home/mailing addressesSocial Security numbers
Order details and plan/order historyConfirmed Trump family member records

The Register, Cybernews and the International Business Times all describe the same core fields: names, emails, phone numbers, home addresses and order or "telecom" details. None of the outlets that examined the sample reported finding payment-card data or passwords in it. Straight Arrow News reported that it found no records belonging to President Trump or members of his family in the dataset, according to coverage of its reporting.

The Eric Brunnett detail

One name researchers flagged in the dataset is Eric Brunnett, described in Cybernews' reporting as the Trump Organization's vice president and chief information officer, with responsibility that reportedly spans IT and information security for the organization. Cybernews reported that Brunnett's own customer record — the same type of contact and order information as other entries — appeared in the leaked file.

It is important to be precise about what this does and doesn't mean: being named in a customer dataset indicates that an executive's own account information was collected as a Trump Mobile customer, not that his personal accounts, devices or the Trump Organization's broader IT systems were separately compromised. Reporting on this detail, including from Cybernews and IBTimes, treats it as a notable coincidence rather than evidence of a deeper intrusion into Brunnett's own systems, and no outlet has independently verified BYOD's broader claims about ongoing network access.

Key facts, according to published reporting
  • Group name: BYOD, claiming responsibility via its dark-web leak site
  • Records: 3,615 customers, per BYOD's own claim and Cybernews' review
  • Data types: names, emails, phone numbers, home addresses, order details
  • Not reported in the leak: passwords, card numbers, Social Security numbers
  • Alleged entry point: an infected employee device at network partner Liberty Mobile
  • Company response: no public statement from Trump Mobile or the Trump Organization as of publication

How the breach allegedly happened

According to BYOD's own account, relayed by both The Register and Cybernews, the group says it first compromised a device belonging to an employee of Liberty Mobile, the Florida-based MVNO that provides the underlying wireless network Trump Mobile runs on. BYOD claims it used an infostealer or remote-access trojan to gain that initial foothold, then pivoted into exposed Trump Mobile subdomains to extract customer records. The group has also claimed it retains ongoing, live access to a backend dashboard used to manage the service — a claim that, as of this writing, has not been independently verified by any outlet that has reported on the leak.

BYOD further told at least one outlet that neither Trump Mobile nor Liberty Mobile appeared to be using multi-factor authentication on the relevant systems. That claim, too, comes solely from the attackers and has not been confirmed by either company. Readers should treat every detail in this section as an attacker's account of events unless and until Trump Mobile, Liberty Mobile or an independent forensic investigation confirms it.

Has Trump Mobile responded?

No. As of this article's publication, Trump Mobile, Liberty Mobile and the Trump Organization have not issued any confirmed public statement acknowledging the BYOD leak, and a check of trumpmobile.com turned up no breach notice, security advisory or press statement addressing it. The Register reported that neither the Trump Organization nor Liberty Mobile responded to its questions about the incident.

BYOD itself claims that after it notified Trump Mobile of the intrusion, a company representative told the group "we have no team to handle this" and separately described hackers in general as "terrorists." Both quotes, as reported by The Register and Cybernews, originate solely with BYOD and have not been corroborated by any statement from Trump Mobile. Because there is no official confirmation on either side, this article treats the breach as an unconfirmed, attacker-claimed incident rather than an established fact, consistent with how this desk has covered other unconfirmed breach disclosures.

A separate, earlier exposure

This is not the first time Trump Mobile customer data has surfaced publicly. In May 2026, security researchers reported a separate website vulnerability in Trump Mobile's T1 phone pre-order system, which they said could be triggered with a simple web request, exposing names, mailing addresses, emails and order details for a large number of pre-order customers. Coverage at the time, including from CyberInsider, cited figures in the range of roughly 27,000 to 30,000 affected records, based on internal order identifiers reviewed by the researchers who flagged the issue. Trump Mobile acknowledged that earlier exposure and said at the time that it had found no evidence that payment card data, banking information or Social Security numbers were affected.

That May incident involved a flaw in the company's own pre-order website, which Trump Mobile said it fixed. The October BYOD leak is a distinct claim involving a third-party network partner, a different and much smaller set of 3,615 records, and — unlike the May incident — no public acknowledgment from the company as of this writing. The two episodes should not be conflated, even though both involve Trump Mobile customer data and both center on contact and order information rather than financial details.

Is the data on Have I Been Pwned?

As of this writing, a direct check of Have I Been Pwned turns up no listed breach for "Trump Mobile" or "BYOD." That doesn't rule out a future addition — breach-notification databases are regularly updated as datasets are verified and ingested — but it does mean that, for now, Trump Mobile customers cannot use that specific tool to check whether their email address appears in this particular leak. If you want to understand how that kind of lookup tool works in general and keep checking as new breaches are added, this explainer on Have I Been Pwned walks through how to set up alerts for your own email addresses.

What to do if you're a Trump Mobile customer

Because the exposed fields reportedly center on contact and address information rather than passwords or payment data, the most immediate risks are phishing, impersonation and targeted scams rather than direct account takeover or financial fraud — but the practical steps below are worth taking regardless of how the company eventually characterizes the incident.

  • Watch for phishing and "smishing." With your name, phone number, email and order history potentially in criminal hands, expect more convincing scam texts and emails referencing your actual Trump Mobile order. Don't click links in unsolicited messages about your account, device shipment or billing; go directly to trumpmobile.com or call customer support using a number you look up independently.
  • Be alert to SIM-swap attempts. Phone numbers and account details are valuable to criminals attempting to hijack a number for SIM-swap fraud. If possible, add a PIN or extra verification step on your mobile account and keep an eye out for unexpected "your SIM has been activated" notifications.
  • Change your Trump Mobile account password anyway. Even though no outlet has reported passwords in this specific leak, it's good practice after any breach involving your account, especially if you reuse that password elsewhere.
  • Consider freezing or monitoring your credit. No financial data has been reported as part of this leak, but exposed home addresses and names are often combined with other leaked datasets for identity-theft attempts. A credit freeze is free and reversible.
  • Clean up your public data footprint. Leaked home addresses become more dangerous when they're easy to cross-reference with other public records. Our guide on opting out of data broker and people-search sites walks through removing your address from the sites most likely to be scraped alongside a leak like this.
  • Check your email against future breach-notification tools. The data isn't in Have I Been Pwned yet, but it's worth bookmarking a check for later, the same way it's worth revisiting after other retailer and service breaches, such as the ASOS data breach earlier this year.

Why this matters

Beyond the specific numbers, the episode is a reminder that MVNOs like Trump Mobile depend heavily on third-party network partners — in this case, Liberty Mobile — for core infrastructure, and a security lapse at that partner can expose customer data even if the consumer-facing brand's own website and app are secure. It's the same dynamic that has driven breach disclosures at other companies that outsource infrastructure or customer-data handling to partners, and it underscores why attribution in security reporting matters: a claim from an attacker group is not the same as a confirmed, investigated breach, even when some individual details check out.

It also illustrates a pattern seen across many consumer data leaks: once a sample is public, journalists and researchers can usually confirm that at least part of it is genuine by contacting people named in the records, as Straight Arrow News did here, even while the attacker's full narrative — the entry point, the scope, and whether access is ongoing — remains unverified. This desk has seen a similar gap between attacker claims and confirmed facts play out in other recent breach disclosures, where companies took weeks to confirm, deny or clarify details that a leak group had already published on its own site.

The bottom line

A group calling itself BYOD claims to have obtained and published personal information on 3,615 Trump Mobile customers, reportedly including names, emails, phone numbers, home addresses and order details, with no passwords or payment data reported in the sample. Trump Mobile, Liberty Mobile and the Trump Organization had not issued any public confirmation as of this writing, and BYOD's account of how it gained access remains unverified. Pandromeda will update this story if any of the companies involved issue an official statement or if the dataset is independently confirmed or added to breach-notification services like Have I Been Pwned.

Frequently asked questions

What is the Trump Mobile data breach?

A hacker group calling itself BYOD claims to have leaked personal data on 3,615 Trump Mobile customers, including names, email addresses, phone numbers, home addresses and order details, according to reporting by The Register and Cybernews. Trump Mobile has not confirmed the breach.

How many Trump Mobile customers were affected?

BYOD claims the dataset covers 3,615 customers. Cybernews reviewed samples of the data and said the records appeared to belong to genuine Trump Mobile customers, though the full scope of BYOD's claim has not been independently verified.

What data was exposed in the Trump Mobile leak?

According to The Register, Cybernews and IBTimes, the leaked fields reportedly include names, email addresses, phone numbers, home addresses and order or account details. No outlet has reported finding passwords, card numbers or Social Security numbers in the sample.

Has Trump Mobile confirmed the breach?

No. As of publication, Trump Mobile, its parent the Trump Organization, and network partner Liberty Mobile had not issued any public statement confirming or denying the BYOD leak, and The Register reported that neither company responded to its questions.

Who is Eric Brunnett and why is he mentioned in coverage of this leak?

Cybernews reported that Eric Brunnett, described as the Trump Organization's vice president and chief information officer, has a customer record included in the leaked dataset. This reflects his own information being listed as a customer, not a reported separate compromise of his personal accounts or systems.

Is the leaked Trump Mobile data on Have I Been Pwned?

Not as of this writing. A direct check of Have I Been Pwned turned up no listed breach for Trump Mobile or BYOD, though breach-notification databases are updated over time as datasets are verified.

Sources

More on Trump Mobile →Trump Mobiledata breachBYODLiberty Mobilecybersecurity
Sana Qureshi
Written bySana Qureshi

Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

More from Security & Privacy

See all