A ransomware group calling itself BYOD says it leaked a file containing 3,615 Trump Mobile customer records on a dark-web site, claiming the dataset included names, email addresses, phone numbers, home addresses and order details and naming Eric Brunnett, the Trump Organization’s vice president and CIO, among the entries. BYOD alleges it gained access by installing a Remote Access Trojan on an employee device at Liberty Mobile - the Florida-based provider that powers Trump Mobile’s MVNO - then pivoted to exposed Trump Mobile subdomains and a backend dashboard, supplying a screenshot and claiming ongoing access. The group also reported that Trump Mobile told them it lacked a team to handle the incident and characterized intruders as terrorists; BYOD has since distanced itself from another group, Endzone, which recently claimed a separate Trump Mobile theft.
Independent checks by PCMag contacted three people listed in the leak who confirmed interactions with Trump Mobile, and Straight Arrow News found additional corroborating entries, though not every record was verified and no passwords or payment card numbers were shown in published data. Security experts warn exposed contact and order information could fuel phishing or social‑engineering attacks. Key questions remain unresolved: whether the alleged backend access is still live, the exact infection vector and malware family, and how broadly customers’ data may be affected.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.