Ransomware victim disclosure
← All victimsTrump Mobile
Claimed by EndZone · listed 2 hours ago
Status timeline
- ListedSep 23, 2026
- Data leakeddate unknown
At a glance
- Group
- EndZone
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Sep 23, 2026
About the victim
AI dossier — public-source company profileTrump Mobile is an American mobile virtual network operator (MVNO) operating under a licensed brand from the Trump Organization, launched by Donald Trump Jr. and Eric Trump. The service operates with approximately 4,000 users.
- Industry
- Mobile Virtual Network Operator (MVNO)
Attack summary
Severity: medium — Confirmed exfiltration of PII and technical authentication data (eSIM QR codes) affecting a small user base (~4,000 users). No proof files advertised; moderate sensitivity due to PII exposure but limited scale relative to larger carriers.EndZone claims to have exfiltrated user data from Trump Mobile, including eSIM QR codes and personally identifiable information (PII) from the subscriber base.
Data the group says was taken
AI dossier — extracted from the leak post- eSIM QR codes
- user PII
What the group claims
Revenue: 4K Users Trump Mobile is an American mobile virtual network operator (MVNO) that uses a licensed brand from the Trump Organization and was launched by Donald Trump Jr. and Eric Trump. THEY GOT FKED LOL. ONLY 4K USERS? LOL Includes eSIM QR codes and user PII.
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

