A hacking group calling itself BYOD says it stole personal data belonging to 3,615 Trump Mobile customers. The group claims it got in by infecting an employee of Liberty Mobile with malware. Liberty Mobile is the MVNO that actually operates Trump Mobile’s service on a host network. The breach was disclosed on October 5, 2026.

The sharpest detail is not the subscriber count. One person told PCMag their email address and phone number were still in Trump Mobile’s system. They had started a signup and never finished it. People who decided against the service were exposed by it anyway.
Two outlets checked the hackers’ claim rather than taking it at face value. PCMag and Straight Arrow News each contacted people named in the leaked dataset. Several of those people confirmed their details were accurate.
What was exposed in the Trump Mobile data breach
PCMag reports that the dataset includes names, home addresses, email addresses and phone numbers. It also carries order and plan information, including cancellation details. That combination is more than enough for convincing phishing or a SIM-swap attempt.
BYOD told PCMag it had hit a hard ceiling on the number. It said that figure is all the MVNO subscribers the carrier has.
“We only stole 3,615 customers due to the fact that’s all they have using their MVNO”
The group also says it had live access to an internal dashboard. It separately denied any link to another group referred to as Eteam, or Endzone. It was asked directly whether the two leaks were connected.
Abandoned signups were kept anyway
Retaining contact details from signups people walked away from is a choice, not a technical accident. It widens the blast radius of any breach, because the exposed group is larger than the customer base. Nobody who abandoned a signup expected to be in that dataset.
Another customer told PCMag they were blocked from buying a phone because their email was already in the system. That is the same retention problem surfacing as a second, smaller annoyance.
A second incident this year
This is not Trump Mobile’s first security problem of 2026. PCMag reports that a separate software vulnerability capable of exposing customer information was found in May 2026. Treat that as background from PCMag’s reporting rather than a separately audited finding.
BYOD also claims that when Trump Mobile was told about the intrusion, the reply was that it had no team to handle it. That is the attackers’ account of the exchange, not a verified company statement. As of October 7, no on-record comment from Trump Mobile has surfaced.
Still, the scope here matters more than the brand. A carrier that resells someone else’s network depends on that partner’s security, and customers get no visibility into either side. The 3,615 figure is also the hackers’ own count rather than the result of an independent forensic audit. The real total could differ.
What affected customers should do
- Add a carrier PIN or port-out lock. Leaked names, numbers and plan details are the raw material for SIM-swap fraud.
- Expect targeted phishing. A message that correctly cites your plan or a recent cancellation is not proof it came from your carrier.
- Move two-factor codes off SMS. An authenticator app or a passkey survives a hijacked phone number.
- Watch the email address you used. It may still be in the system even if you never completed signup.
It is also worth tightening what your messaging app exposes by default. Our walkthrough of Google Messages RCS settings covers the toggles most people never open.
Sources: PCMag, Straight Arrow News




