Trump Mobile Wireless Data Breach

Alleged

Ransomware claim involving Trump Mobile Wireless

Published: Oct 5, 2026 BYOD
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Trump Mobile Wireless
Industry
Manufacturing
Threat Actor
BYOD
Date of Incident
Oct 5, 2026

Executive Summary

BYOD listed Trump Mobile Wireless, a US telecommunications company, on October 5, 2026. The group claims unauthorized access to subscriber systems and data. SOCRadar CTI identified 8 business application credential records associated with the domain trumpmobile[.]com, spanning from February to September 2026. This seven-month period suggests exposure of customer-facing portals. BYOD has claimed 3 victims in the past 60 days, including Trump Mobile Wireless and Royal Selangor, along with other organizations in manufacturing and technology sectors in Malaysia and the United States. The group’s small victim count and cross-regional targeting, coupled with a focus on consumer-facing brands, indicates a prioritization of companies with large subscriber databases and potential reputational vulnerability.

Technical Analysis

SOCRadar’s CTI analysis revealed 8 records for trumpmobile[.]com, all of which were business application credentials. These records were dated between February and September 2026. The exclusive presence of application-layer credentials, rather than corporate domain or workstation artifacts, suggests a focus on customer account takeover rather than deep internal network compromise. This type of data is consistent with credentials stolen from subscriber portals, billing systems, or service management interfaces. For a telecommunications provider like Trump Mobile Wireless, such exposed credentials pose specific risks. These include the potential for SIM-swapping attacks, unauthorized account access, and fraudulent service changes. The seven-month exposure window indicates that customer credentials have been available to threat actors since at least February, increasing the potential for malicious activity. The identified response priorities for Trump Mobile Wireless include auditing all active subscriber sessions within the February to September exposure window. Implementing multi-factor authentication across customer portals is crucial. Additionally, the company should investigate SIM swap requests and unauthorized account changes that occurred during the exposure period. Customer notifications may be necessary, depending on the extent of accessed account data.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.