If you signed up for Trump Mobile, you may be part of an exclusive club of … ransomware victims. Criminals called BYOD claim to have broken into the Trump-branded mobile biz and leaked data belonging to 3,615 people, including names, email addresses, phone numbers, home addresses, and order details. BYOD is a new ransomware-as-a-service operation, and Trump Mobile is only the third organization posted on its data-leak site. According to the group’s posted claim, after telling Trump Mobile that it had been breached, the wireless provider replied: “We have no team to handle this” and “Anyone who hacks them are a terrorist.” “Well unfortunately for them, all 3615 customers and their PII, alongside telecom details are now up for grabs,” the leak site says. “Feel free to take a gander at it yourself, don’t be shy, we (and them) certainly aren’t stopping you.” The hackers reportedly told International Cyber Digest that they first infected a Liberty Mobile employee with an infostealer, and then accessed Trump Mobile via the MVNO. BYOD claims to still have access to Trump Mobile’s systems, and told the publication that neither wireless provider used any form of multi-factor authentication. Neither the Trump Organization nor Liberty Mobile responded to The Register’s questions about the breach. The data dump doesn’t include any details about US President Donald Trump or his family members, according to Straight Arrow News, which first reported the breach and verified some customers’ information. This could mean that the Trump family doesn’t eat its own dogfood. The leak does, however, include personal information about Eric Brunnett, vice president and chief information officer for the Trump Organization. Brunnett’s LinkedIn profile says he oversees “all Information Technology and Information Security for all aspects of the Trump Organization.” Additionally, one customer contacted by Straight Arrow said he paid a $100 pre-order deposit last year for Trump Mobile’s flagship smartphone, the T1, but never received a gold-colored device. Another criminal group, EndZone, also claimed to have breached Trump Mobile and leaked a stolen dataset a week before BYOD’s post in what “appears to be the same original breach,” according to security sleuth Dominic Alvieri. These aren’t the fledgling mobile phone company’s only security snafus. Before these two apparent breaches, a security researcher in May claimed he discovered a now-plugged website vulnerability that leaked Trump Mobile customers’ details. The individual behind the discovery, who goes by “Louis” and described himself as “just a nerd between jobs with too much time on my hands,” previously told The Register that the website’s data could be scooped up with a simple POST request.®

