Ransomware group exposes data of 3,615 Trump Mobile customers
Trump Mobile customers have been compromised in a data breach affecting 3,615 people, with a ransomware group called BYOD claiming responsibility for stealing personal information including names, email addresses, phone numbers, home addresses and order details. The breach highlights serious security lapses at the startup mobile company, as the hackers reportedly gained access through an infected Liberty Mobile employee and found neither company had implemented multi-factor authentication.
The attack marks the third breach reported against Trump Mobile in recent months, following similar claims by another criminal group called EndZone and a separate vulnerability discovered earlier this year. Notably, one customer reported paying a $100 deposit for the company's flagship T1 smartphone but never receiving the device, whilst the leaked information includes details of Eric Brunnett, the Trump Organisation's vice president and chief information officer. When initially contacted about the breach, Trump Mobile reportedly responded that it had "no team to handle this," before the hackers published the stolen data online.
- Ransomware group BYOD leaks personal data of 3,615 Trump Mobile customers in latest breach
- Neither Trump Mobile nor Liberty Mobile used multi-factor authentication to protect systems
- Third reported security incident for Trump Mobile in recent months
New here? Start with this
Trump Mobile is a startup mobile phone company that has experienced multiple data breaches in recent months. A ransomware group called BYOD has claimed responsibility for stealing customer information from the company, affecting 3,615 people.
The stolen information included names, email addresses, phone numbers, home addresses and details of customer orders. This type of data can be used for fraud, identity theft or targeted scams, posing a risk to those affected.
This is the third breach to affect Trump Mobile in recent months. Hackers reportedly accessed the system through an infected employee at a linked company and found that the startup had not implemented basic security measures such as multi-factor authentication on its systems.
Read the full article at the source →
Originally published by The Register as “Trump Mobile customers’ data dumped – and some never even received their gold device”.