Tech
Supply-chain compromise | Trojan infection at partner MVNO triggers data leak
A ransomware crew called BYOD published 3,615 Trump Mobile customer records after infecting a Liberty Mobile employee workstation with a Remote Access Trojan, exposing the risks of the MVNO supply chain.

The security architecture of celebrity- and politician-branded telecommunications offerings has come under severe scrutiny following a major third-party cyber incident.
A ransomware operation operating under the moniker BYOD has published a dataset containing the personally identifiable information (PII) and order histories of 3,615 Trump Mobile customers onto a dark-web leak site.
Initial technical forensic investigations confirm that the intrusion did not originate from a direct breach of Trump Mobile's primary web assets. Instead, the attackers executed a supply-chain attack by infecting an employee at Liberty Mobile, the Florida-based Mobile Virtual Network Operator (MVNO) that powers Trump Mobile's backend network infrastructure, using a Remote Access Trojan (RAT).
The incident ledger | Trump Mobile data breach profile
The leak represents the latest in a series of security vulnerabilities affecting the mobile service since its launch.
Trump Mobile Incident Matrix (October 2026)
| Target Platform | Trump Mobile (operated via Liberty Mobile / T1 Mobile) |
| Threat Actor | BYOD (Ransomware-as-a-Service group) |
| Primary Attack Vector | Remote Access Trojan (RAT) infostealer on third-party MVNO workstation |
| Total Confirmed Leaked Records | 3,615 unique customer profiles |
| Exposed Data Classes | Names, phone numbers, email addresses, physical mailing addresses, $100 deposit logs, plan selections |
| High-Profile Record Included | Eric Brunnett (VP and Chief Information Officer, The Trump Organization) |
Technical anatomy of the breach | The infostealer vector
According to statements provided by the threat actors and verified by cybersecurity researchers, the attackers deployed an infostealer malware package to establish persistent access on a contractor's device.
Because neither Liberty Mobile nor the subsidiary platform employed mandatory multi-factor authentication (MFA) across administrative dashboards, the credentials harvested by the Trojan allowed the hackers to move laterally into backend customer portals.
The Attack Sequence
Independent verification of the dataset by cybersecurity firms confirmed that while no financial account numbers or Social Security numbers were included in the published file, the records contained highly accurate customer order details, including $100 pre-order deposits for the brand's flagship T1 smartphone and active wireless plan selections.
Notably, among the leaked records was the personal contact information of Eric Brunnett, the Vice President and Chief Information Officer for The Trump Organization, who oversees technology operations for the enterprise. No members of the Trump family were identified within the compromised dataset.
Third-party risks in the MVNO ecosystem
The incident underscores the systemic risks inherent to the Mobile Virtual Network Operator business model.
Brand-focused mobile providers routinely rely on layered third-party infrastructure, combining white-label marketing fronts with underlying network aggregators and major carrier towers. When a contractor or backend partner fails to enforce basic security hygiene, such as applying critical software patches or mandating multi-factor authentication, the customer data of the front-facing brand remains highly vulnerable.
With threat actors claiming to retain ongoing access to administrative management dashboards, cybersecurity analysts warn that exposed customers face an elevated risk of targeted SIM-swapping, phishing campaigns, and credential-stuffing attacks.
OnyxTimes will continue to track the cybersecurity landscape. For related coverage of supply-chain and data breach threats, see our reports on the North Korean IT worker infiltration and McDonald's 515-page consumer dossier.