A brand-new ransomware gang says it hacked Trump Mobile, told the company about it, and got back the corporate equivalent of a shrug: 'We have no team to handle this.' The result is that personal data on 3,615 customers is now sitting on a dark web leak site, including details about the Trump Organization's own chief information officer, the guy whose LinkedIn page says he oversees all IT and information security for the whole empire.
The Gang With the Most Relatable Name in Cybercrime
According to reporting from Straight Arrow, the group behind the hack calls itself BYOD, which is the kind of name that sounds like it came out of a quarterly IT compliance meeting. It is a ransomware gang that is apparently brand new, and it posted the stolen data to its dark web leak site last week with a statement that reads like a customer service complaint.
"Trump mobile was informed they had been breached, they then replied with 'We have no team to handle this' and that anyone who hacks them are a terrorist," the group wrote. "Well unfortunately for them, all 3615 customers and their PII, alongside telecom details are now up for grabs."
They then invited the public to take a look. "Don't be shy," they wrote, "we (and them) certainly aren't stopping you." That last part is the funniest and most damning line in the whole thing, because it appears to be true.
What Got Leaked
Straight Arrow analyzed the data and found first and last names, email addresses, phone numbers, home addresses, and order details. That is a full starter kit for identity fraud, phishing, and your weirdest uncle's favorite hobby, getting a stranger's address and showing up in a Facebook comment section.
Some entries show purchases of mobile data plans, including a "30 Day Unlimited Talk Text Data" plan. Others tie back to the famously troubled T1 phone. One customer confirmed by phone that he put down a $100 deposit last year for the flagship T1 and never received a device.
He is not alone in that. In May, Straight Arrow reported that 590,000 people had paid $100 deposits and were still waiting on phones as much as 11 months later. So the Trump Mobile customer experience, as it currently stands, is paying money, receiving nothing, and then having your home address posted online for free.
The Trump Organization's IT Chief Is in the Spreadsheet
No member of the Trump family showed up among the exposed customers. Straight Arrow's review did find Eric Brunnett, the Trump Organization's vice president and chief information officer. His LinkedIn profile says he oversees "all Information Technology and Information Security for all aspects of the Trump Organization."
Read that again. The man in charge of information security for the entire Trump Organization had his own personal details exposed in a hack of a phone company that carries the Trump name. I'm not saying that's a bad look. I'm saying a bad look would be an improvement.
Another Trump Organization employee turned up too. Nicholas Hayes, listed by the Florida Bar as a Trump Organization lawyer based in Florida, confirmed by phone that he had used Trump Mobile in the past but no longer does. So even the people on the payroll have apparently moved on.
How the Hackers Say They Got In
A BYOD representative told Straight Arrow the group got access by infecting an employee at Liberty Mobile, a Florida-based company, with malware. Trump Mobile is owned by T1 Mobile, which uses a licensed brand from the Trump Organization. In other words, the Trump name is on the box, but the plumbing belongs to somebody else, and the plumbing leaked.
The representative also claimed the group still has access to Trump Mobile's backend dashboard and sent Straight Arrow a screenshot showing personal data on a customer. That is a claim from a criminal gang, so treat it accordingly. But it matters that the screenshot exists, and that Trump Mobile had not responded to Straight Arrow's request for comment at the time of publication.
Several other people Straight Arrow contacted confirmed their exposed information was accurate, then denied being customers and hung up. There is something almost poetic about people verifying their own leaked data and then insisting they have never heard of the company.
A Very Short History of Trump Mobile Going Well
Trump Mobile was announced last year by Eric Trump and Donald Trump Jr., shortly after their father returned to the White House. It promised a gold-colored phone made in America. Then the company quietly scrubbed the made-in-America language from its promotional material.
Then came the waiting. Hundreds of thousands of deposits, months of silence, and no phones. Shipping reportedly began in May, shortly after Straight Arrow's reporting on the delays. Now the customer database is on the open internet.
So the track record so far is a broken manufacturing promise, an enormous delivery delay, and a data breach where the company's reported response to being told about the problem was that it had no one to handle it. If this were a restaurant, the health inspector would be bringing a priest.
The Dingo Take
Trump Mobile reportedly told a ransomware gang it had no team to handle a breach, and then the breach happened anyway. That is the whole review. Five stars, would get hacked again.
Look, a phone company that cannot deliver phones, cannot keep its manufacturing promises, and cannot secure the names and home addresses of fewer than four thousand people is not a cutting-edge disruptor. It is a brand license with a customer service problem. The people who actually paid the price are ordinary customers who handed over $100 and their personal information because the name on the box told them to trust it.
And the Trump family got the rewards of a name on a product while the customers got the exposure. Somebody in that data set is going to get a phishing email with their real address in it, and it will have come from a company that was too busy to build an incident response team. Meanwhile the guy running security for the whole Trump Organization is in the spreadsheet too. At least the leak was egalitarian.




Comments