Trump Mobile is facing another alleged data breach after a threat actor published claims involving the personal information of 3,615 customers. The dataset reportedly contains names, email addresses, phone numbers, physical addresses and order information.
The information was advertised on October 11, 2026, with the threat actor attributing the compromise to the cybercriminal group BYOD.
According to the claim, attackers gained access by infecting an employee of Liberty Mobile, a Florida-based telecommunications provider associated with Trump Mobile, with malware.
The alleged intrusion method and the authenticity of the advertised dataset have not been independently verified.
Customer information allegedly compromised
The threat actor claims the exposed records contain:
- Full names
- Email addresses
- Phone numbers
- Residential addresses
- Customer order information
If authentic, the information could facilitate targeted phishing, impersonation attempts and scams involving fraudulent order notifications or telecommunications support.
The attacker also alleged that Trump Mobile support personnel dismissed attempts to report the incident. Those statements remain unverified.
Previous exposure and questions over third-party security
The latest claim follows a separate customer data exposure acknowledged by Trump Mobile in May 2026. At that time, the company attributed the incident to a third-party platform provider and said it had found no evidence that its own network or infrastructure had been compromised.
The October allegations have also attracted regulatory attention. In an October 8 statement, U.S. Senator Maggie Hassan raised concerns about Trump Mobile’s customer data protections and its relationship with Liberty Mobile.
The senator’s office also noted that separate September and October breach claims may involve the same underlying incident. Consequently, the latest listing should not automatically be treated as evidence of a new compromise.
Trump Mobile and Liberty Mobile had not issued public statements confirming the October breach allegations at the time of publication.










