Customers of Trump Mobile may be among the latest victims of a ransomware attack. The group BYOD claims to have breached the Trump-branded mobile provider and leaked the personal data of 3,615 individuals, as first reported by The Register.
The ransomware-as-a-service operation BYOD posted customer names, email addresses, phone numbers, home addresses, and order details on its data-leak site. According to BYOD, Trump Mobile's response to the breach notification was dismissive, stating they had no team to handle such incidents. The hackers reportedly gained access through an employee of Liberty Mobile, an MVNO that operates Trump Mobile, after infecting the employee with an infostealer.
BYOD claims neither Trump Mobile nor Liberty Mobile employed multi-factor authentication. The leaked data includes personal information of Eric Brunnett, vice president and CIO for the Trump Organization. This incident follows a previous data leak by another group, EndZone, and a website vulnerability discovered in May that exposed customer details. Neither the Trump Organization nor Liberty Mobile have responded to inquiries regarding the breaches.
Source: The Register
