Affiliate links on Android Authority may earn us a commission. Learn more.
Hackers leak info on 3,615 Trump Mobile subscribers, and that's all they seemingly had
Oct 7, 2026 — 4:04 AM ET

- Threat actor group “BYOD” published 3,615 customer records belonging to Trump Mobile subscribers on the dark web.
- Hackers allegedly gained entry via a remote access trojan (RAT) on an employee device at partner MVNO Liberty Mobile.
- Exposed files include sensitive personal details of active subscribers and abandoned checkout data. However, this does not include data from Trump Mobile T1 phone orders.
Trump Mobile has already faced intense scrutiny this year over steep price hikes on its T1 smartphone, questionable hardware specs, and shipping delays. Now, the controversial smartphone brand is facing another major crisis after a hacking group published personal records allegedly belonging to thousands of its customers on the dark web. According to the threat actors, the compromised data exposes virtually the entire brand’s active subscriber base.
As reported by Straight Arrow News (via PCMag), a hacking group operating under the moniker “BYOD” claimed responsibility for exfiltrating and dumping customer files containing details of 3,615 accounts. The exposed data allegedly includes customer names, email addresses, phone numbers, home addresses, order histories, and plan cancellation records. Notably, the leak also allegedly contains the personal details of Eric Brunnett, Vice President and Chief Information Officer of the Trump Organization, which licenses its branding to the service.
Independent outreach by reporting outlets confirmed that multiple individuals listed in the leaked dump had indeed interacted with or signed up for Trump Mobile.
The hackers stated that they gained entry by compromising an employee with a remote access trojan (RAT) at Liberty Mobile, the Florida-based mobile virtual network operator (MVNO) infrastructure partner powering Trump Mobile’s network. Explaining the relatively modest total count, BYOD claimed, “We only stole 3,615 customers due to the fact that’s all they have using their MVNO.” Note that these are people using the carrier, and are different from the Trump Mobile T1 phone orders.
Disturbingly, the dataset also includes records of prospective buyers who abandoned their (carrier) orders mid-signup, revealing that Trump Mobile retained user contact information even when transactions were never completed.
When the threat actors allegedly alerted Trump Mobile to the intrusion, the company reportedly said it had no dedicated internal team available to handle the incident, and that “anyone who hacks them [is] a terrorist.” The company has not yet issued a formal public response.
If you have ever engaged with Trump Mobile or submitted your contact details on its portal, you should treat your information as potentially exposed and remain vigilant against phishing attempts referencing your order status.
Thank you for being part of our community. Read our Comment Policy before posting.