Ransomware victim disclosure
← All victimsTrump Mobile Wireless
listed as Trump Mobile Wireless (Telecom) · Claimed by BYOD · listed 23 hours ago
Status timeline
- ListedOct 5, 2026
- Data leakeddate unknown
At a glance
- Group
- BYOD
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Oct 5, 2026
About the victim
AI dossier — public-source company profileTrump Mobile Wireless is a US-based telecommunications company operating under the domain trumpmobile.com. The company provides mobile wireless services to customers.
- Industry
- Telecommunications
Attack summary
Severity: high — Confirmed exfiltration of PII at significant scale (3,615 customers) combined with telecommunications data from a telecom provider. While no proof files are explicitly quantified in the post, the data types are sensitive and regulatory impact likely.BYOD claims to have exfiltrated data on approximately 3,615 customers, including personally identifiable information (PII) and telecommunications details. The group alleges the company responded to breach notification with inadequate incident response.
Data the group says was taken
AI dossier — extracted from the leak post- Customer PII
- Telecommunications details
- Customer account information
What the group claims
Trump mobile was informed they had been breached, they then replied with "We have no team to handle this" and that anyone who hacks them are a terrorist. Well unfortunately for them, all 3615 customers and their PII, alongside telecom details are now up for grabs. Feel free to take a gander at it yourself, don't be shy, we (and them) certainly aren't stopping you.
Sources
- Victim sitetrumpmobile.com
Source
Indexed 23 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

