Trump Mobile Customer Data Leaked After Alleged Infostealer Attack on Partner Provider
A new ransomware-as-a-service group called BYOD claims it has broken into Trump Mobile and published data on 3,615 people. The leaked information reportedly includes names, email addresses, phone numbers, home addresses and order details. Trump Mobile is only the third organisation listed on the group's data-leak site. Neither the Trump Organization nor Liberty Mobile responded to The Register's questions about the breach.
According to the hackers, they first infected a Liberty Mobile employee with an infostealer, a type of malware that harvests saved logins. They then reached Trump Mobile through the mobile virtual network operator (MVNO) relationship between the two companies. BYOD told International Cyber Digest that neither provider used any form of multi-factor authentication, and claims it still has access to Trump Mobile's systems. These claims are unverified. Straight Arrow News, which first reported the breach, verified some customers' information. The leak reportedly includes details of the Trump Organization's chief information officer, but nothing about the Trump family. One customer said he paid a $100 pre-order deposit for the T1 phone and never received it.
Another group, EndZone, claimed to have leaked a stolen dataset a week earlier in what security researcher Dominic Alvieri said appears to be the same original breach.