2 Remove Virus

Hackers threaten T-Mobile after leaking thousands of Trump Mobile customer records

A newly emerged ransomware group has claimed to have stolen data from T-Mobile, one of the largest wireless carriers in the United States. The allegation comes just days after the same group published personal information belonging to thousands of Trump Mobile customers.

 

 

The group, known as BYOD, added T-Mobile to its dark web leak site on October 7, warning the telecommunications company to establish contact. The attackers also posted a separate message on a hacking forum to draw attention to their claim.

However, the group has not released any stolen files or samples that would demonstrate access to T-Mobile’s systems. The alleged breach remains unverified, and there is currently no confirmed information about what data, if any, the attackers obtained.

T-Mobile serves approximately 142 million customers across the United States and is majority-owned by German telecommunications company Deutsche Telekom. A successful attack against such a large provider could have significant consequences, although there is no evidence at this stage that customer information has been compromised.

BYOD is a relatively new operation that appeared in late September 2026. By October 8, the group had listed eight alleged victims on its website, but its organizational structure and exact methods remain unclear.

The gang recently attracted attention after publishing information associated with 3,615 Trump Mobile customers. The exposed records reportedly included names, email addresses, telephone numbers, home addresses, and details of purchases or orders.

Independent reporting confirmed that some of the leaked information matched details provided by affected individuals. The attackers claimed they had gained access through malware installed on a computer belonging to an employee of Liberty Mobile, a company involved in providing Trump Mobile’s wireless services.

That explanation has not been independently verified. The group also claimed it retained access to Trump Mobile’s administrative systems after publishing the information.

The latest threat against T-Mobile follows several previous attempts by cybercriminals to associate major telecommunications companies with alleged data breaches. In 2025, attackers claimed to possess 64 million T-Mobile records, but the company denied that the published information originated from its systems or customers.

Deutsche Telekom has also appeared in earlier ransomware claims, demonstrating how major telecommunications brands can become targets of extortion attempts even when the attackers’ allegations remain unproven.

At the time of reporting, T-Mobile had not issued a public response to BYOD’s latest claim. The attackers have provided no supporting evidence, leaving the existence and potential scope of the alleged intrusion uncertain.