A claim has been raised that user information on more than 3,600 people was stolen from Trump Mobile, a mobile service branded with the name of U.S. President Donald Trump.
On Oct. 6 local time, IT outlet The Verge reported that the newly formed hacking group BYOD claimed it had obtained personal information for 3,615 people related to Trump Mobile. The leaked data reportedly include names and home addresses, email addresses, phone numbers and order-related information.
The total scale of the leak has not been independently confirmed, but indications that real personal data were included have been verified. PCMag contacted 3 people on the list directly and received responses that some information matched reality. One of them said they did not complete the Trump Mobile sign-up process but entered an email address and phone number. That raises the possibility that information on potential customers who did not complete registration was also stored.
The leaked material is also said to include information related to Eric Brunnett, the IT chief at the Trump Organization.
BYOD claimed it gained access to internal systems after infecting a device belonging to an employee of Liberty Mobile Wireless, which supports Trump Mobile’s mobile operations, with a remote-access trojan (RAT). It said the account initially had limited privileges, but it later moved to a Trump Mobile-related subdomain and extracted data. The group also claimed it can access the Trump Mobile website management dashboard in real time. This, too, has not been independently verified.
Trump Mobile is a mobile virtual network operator (MVNO) that does not have its own network. The company’s terms and conditions state that its mobile service relies on external networks, and Liberty Mobile Wireless is known to support actual network operations.
The outlet added, "We asked Trump Mobile for comment but did not receive an immediate response." For now, only BYOD’s claims and whether some leaked information is authentic have been confirmed, so further investigation is needed to determine the actual scope of the breach and the number of victims.