"We have no team to handle this."
BYOD posts 3,615 Trump Mobile customers' records
Criminals calling themselves BYOD say they have published personal data for 3,615 people who signed up for Trump Mobile, the Trump-branded wireless provider. The group — described in reporting as a new ransomware-as-a-service operation — posted the dataset on its data-leak site and wrote that the dump includes names, email addresses, phone numbers, home addresses, and order details.
In the same post the leak site quoted an alleged reply from the wireless provider after being told it had been breached: "We have no team to handle this" and "Anyone who hacks them are a terrorist." The BYOD post went on: "Well unfortunately for them, all 3615 customers and their PII, alongside telecom details are now up for grabs… Feel free to take a gander at it yourself, don't be shy, we (and them) certainly aren't stopping you."
Attack path alleged: infostealer, MVNO access, and no MFA
BYOD told International Cyber Digest that the intrusion began when an employee of Liberty Mobile — the mobile virtual network operator (MVNO) used by Trump Mobile — was infected with an infostealer. According to those claims, the attackers then used that foothold to access Trump Mobile's systems via the MVNO.
BYOD also told the publication that neither wireless provider used any form of multi-factor authentication, and the group claimed it still has access to Trump Mobile’s systems.
Neither the Trump Organization nor Liberty Mobile responded to The Register’s questions about the breach, the reporting says.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadSeparate claims and an earlier web vulnerability
The data release followed a claim by another criminal group, EndZone, which said it had breached Trump Mobile and leaked a stolen dataset a week earlier. Security sleuth Dominic Alvieri told reporters that EndZone's dump "appears to be the same original breach."
Before the two apparent intrusions, a security researcher who goes by "Louis" said in May that he had discovered a website vulnerability that exposed Trump Mobile customers' details. Louis — who described himself as "just a nerd between jobs with too much time on my hands" — told The Register the site's data could be scooped up with a simple POST request. That vulnerability has since been plugged, the reporting says.
Named individuals: Eric Brunnett and an unpaid T1 pre-order
The leaked dataset, Straight Arrow News reported and verified in part, does not include any details about US President Donald Trump or his family members. It does, however, contain personal information for Eric Brunnett, identified in the leak as the vice president and chief information officer for the Trump Organization. Brunnett's LinkedIn profile — cited in reporting — says he is responsible for "all Information Technology and Information Security for all aspects of the Trump Organization."
Straight Arrow News also quoted a customer who said he paid a $100 pre-order deposit last year for Trump Mobile’s flagship smartphone, the T1, but never received a gold-colored device. That unfulfilled order is one of the consumer harms visible in the leaked records.
What this means for Trump Mobile customers, the Trump Organization, and Liberty Mobile
- Trump Mobile customers: Thousands of individuals now face the immediate reality of exposed names, contact details and order histories; Straight Arrow News verified some customers’ information from the leak.
- The Trump Organization: The presence of Eric Brunnett’s personal information in the dataset ties the breach into corporate IT leadership, given Brunnett’s stated oversight of information security on his LinkedIn profile.
- Liberty Mobile: BYOD’s account links the incident to an infected Liberty Mobile employee and to MVNO access, and the group claims neither provider used multi-factor authentication; Liberty Mobile did not respond to questions from The Register, according to the reporting.
The public record published so far is stark about who claims responsibility, what was posted, and which parties were contacted for comment. BYOD insists it retains access to Trump Mobile systems, EndZone earlier claimed the same underlying breach, and researchers previously found a now-remediated site flaw that could have exposed customer data. Neither the Trump Organization nor Liberty Mobile provided answers to The Register’s inquiries, leaving open whether the intrusion has been fully contained or whether additional notifications or remedies will follow.




