ONYXTIMES

Tech

Supply-chain compromise | Trojan infection at partner MVNO triggers data leak

A ransomware crew called BYOD published 3,615 Trump Mobile customer records after infecting a Liberty Mobile employee workstation with a Remote Access Trojan, exposing the risks of the MVNO supply chain.

By Andrew C. Cardone5 min readTech
Mobile phone and network infrastructure representing the Trump Mobile data breach

The security architecture of celebrity- and politician-branded telecommunications offerings has come under severe scrutiny following a major third-party cyber incident.

A ransomware operation operating under the moniker BYOD has published a dataset containing the personally identifiable information (PII) and order histories of 3,615 Trump Mobile customers onto a dark-web leak site.

Initial technical forensic investigations confirm that the intrusion did not originate from a direct breach of Trump Mobile's primary web assets. Instead, the attackers executed a supply-chain attack by infecting an employee at Liberty Mobile, the Florida-based Mobile Virtual Network Operator (MVNO) that powers Trump Mobile's backend network infrastructure, using a Remote Access Trojan (RAT).

The incident ledger | Trump Mobile data breach profile

The leak represents the latest in a series of security vulnerabilities affecting the mobile service since its launch.

Trump Mobile Incident Matrix (October 2026)

Target PlatformTrump Mobile (operated via Liberty Mobile / T1 Mobile)
Threat ActorBYOD (Ransomware-as-a-Service group)
Primary Attack VectorRemote Access Trojan (RAT) infostealer on third-party MVNO workstation
Total Confirmed Leaked Records3,615 unique customer profiles
Exposed Data ClassesNames, phone numbers, email addresses, physical mailing addresses, $100 deposit logs, plan selections
High-Profile Record IncludedEric Brunnett (VP and Chief Information Officer, The Trump Organization)

Technical anatomy of the breach | The infostealer vector

According to statements provided by the threat actors and verified by cybersecurity researchers, the attackers deployed an infostealer malware package to establish persistent access on a contractor's device.

Because neither Liberty Mobile nor the subsidiary platform employed mandatory multi-factor authentication (MFA) across administrative dashboards, the credentials harvested by the Trojan allowed the hackers to move laterally into backend customer portals.

The Attack Sequence

Infostealer / RAT on MVNO Employee Device→Harvested Dashboard Credentials→Unauthenticated Portal Access (No MFA)→Exfiltration of 3,615 Records

Independent verification of the dataset by cybersecurity firms confirmed that while no financial account numbers or Social Security numbers were included in the published file, the records contained highly accurate customer order details, including $100 pre-order deposits for the brand's flagship T1 smartphone and active wireless plan selections.

Notably, among the leaked records was the personal contact information of Eric Brunnett, the Vice President and Chief Information Officer for The Trump Organization, who oversees technology operations for the enterprise. No members of the Trump family were identified within the compromised dataset.

Third-party risks in the MVNO ecosystem

The incident underscores the systemic risks inherent to the Mobile Virtual Network Operator business model.

Brand-focused mobile providers routinely rely on layered third-party infrastructure, combining white-label marketing fronts with underlying network aggregators and major carrier towers. When a contractor or backend partner fails to enforce basic security hygiene, such as applying critical software patches or mandating multi-factor authentication, the customer data of the front-facing brand remains highly vulnerable.

With threat actors claiming to retain ongoing access to administrative management dashboards, cybersecurity analysts warn that exposed customers face an elevated risk of targeted SIM-swapping, phishing campaigns, and credential-stuffing attacks.

OnyxTimes will continue to track the cybersecurity landscape. For related coverage of supply-chain and data breach threats, see our reports on the North Korean IT worker infiltration and McDonald's 515-page consumer dossier.

Sources

  1. 1shattered.io: BYOD Claims Trump Mobile Hack, Leaks 3,615 Records| shattered.io
  2. 2PCMag: Hackers Stole Data From 3,615 Trump Mobile Customers via RAT| PCMag
  3. 3Cybernews: Trump Mobile Data Breach Exposes 3,615 Users, Including Tech Chief| Cybernews
Trump MobileData BreachRansomwareBYODLiberty MobileMVNOSupply Chain

More Stories