A new hacking group known as BYOD claims to have stolen data on over 3,000 Trump Mobile customers by infecting an employee at a related company with malware, PCMag reported. The breach surfaced after the group published a file on the dark web containing names, phone numbers, email addresses, and physical addresses of users.
BYOD Claims Access via Liberty Mobile Employee
The cybercrime gang gained initial entry by installing a Remote Access Trojan on the device of a worker at Liberty Mobile, a Florida-based mobile virtual network operator (MVNO) that powers Trump Mobile, according to correspondence shared with PCMag. BYOD stated in an email that the initial malware infection granted limited permissions to search prepaid numbers. The group then pivoted to exposed subdomains on TrumpMobile.com to extract the customer records.
We only stole 3,615 customers due to the fact that’s all they have using their MVNO,
BYOD told PCMag, distinguishing the carrier users from separate prepaid phone orders. The gang also asserted that it maintains live access to the dashboard on TrumpMobile.com. When the group allegedly informed Trump Mobile of the breach, the company reportedly replied that it had no team to handle the incident and labeled the hackers as terrorists, according to statements published on BYOD’s dark web site.
Customers confirm details in leaked records
Multiple individuals whose records appeared in the leaked file have confirmed interacting with Trump Mobile in the past. Three people verified their details to PCMag, with one customer expressing surprise that the file accurately reflected the cancellation of a 30-day unlimited plan. Another affected individual stated she never successfully completed a signup or preorder for the branded phone, but noted her email and phone number were already in the system after customer support previously contacted her.
Security issues have previously affected the platform. In May, two YouTubers identified a software flaw on TrumpMobile.com that exposed customer names, phone numbers, and physical addresses. Trump Mobile patched that vulnerability at the time and stated it found no evidence of system compromise. Separately, a different hacking group named Endzone claimed to have stolen data from 4,000 Trump Mobile users last month, though BYOD maintained it has no formal affiliation with Endzone.

Responses and Industry Context
Neither Trump Mobile nor Liberty Mobile has responded to requests for comment regarding the alleged data theft. BYOD has been active for approximately one week, raising speculation among security researchers about whether the group utilized leftover exploits or fresh credentials obtained through the malware attack.
What data did BYOD leak from Trump Mobile?
What specific data fields were included in the leaked file?
The dark web file published by BYOD contained customer names, phone numbers, email addresses, and physical addresses, according to PCMag.
How many customer records did BYOD claim to steal?
BYOD stated it exfiltrated records belonging to 3,615 customers who used the MVNO cellular network.
Which company powers the Trump Mobile network infrastructure?
Liberty Mobile, a Florida-based mobile virtual network operator, provides the underlying network services for Trump Mobile.
Related reading