The ransomware-as-a-service operation BYOD claims to have breached Trump Mobile, a mobile virtual network operator, and leaked data belonging to 3,615 customers. The exposed information includes names, email addresses, phone numbers, home addresses, and order details. BYOD is a new operation, and Trump Mobile is only the third organization listed on its data-leak site.
The group told International Cyber Digest that it first infected a Liberty Mobile employee with an infostealer, then accessed Trump Mobile through the MVNO relationship. BYOD also claims it still has access to Trump Mobile's systems and that neither wireless provider used multi-factor authentication. Neither the Trump Organization nor Liberty Mobile responded to The Register's questions. The leaked data does not include any details about President Donald Trump or his family, but it does include information about Trump Organization CIO Eric Brunnett. One customer told Straight Arrow News he paid a $100 deposit for the gold T1 smartphone but never received it.
Another criminal group, EndZone, posted a stolen dataset a week before BYOD's leak, and security researcher Dominic Alvieri said it appears to be the same original breach. This is not Trump Mobile's first security issue: in May, a researcher named Louis reported a website vulnerability that could expose customer details with a simple POST request. The company has not publicly commented on any of these incidents.