
Ransomware Gang BYOD Claims T-Mobile Breach Days After Trump Mobile Hack
Ransomware operation BYOD has listed T-Mobile on its leak site, claiming to hold data from the US carrier and urging it to establish contact to have the posting removed. The gang last week published details of 3,615 Trump Mobile users.
BYOD threatens T-Mobile
Ransomware gang BYOD listed telecommunications giant T-Mobile on its leak site on October 7, 2026, claiming it had obtained data from the company. In a message to the carrier, the group wrote "You're in big big trouble" and told the company to use the contact details on its site, adding that it would remove the listing once communication had been established. The gang also posted another warning on a well-known hacker forum to put additional pressure on the alleged victim. So far, BYOD has not released any data samples to back up its claims, a common early tactic used by extortion gangs to build leverage.
A newcomer with a growing victim list
BYOD is a newcomer to the ransomware scene, first observed at the end of September 2026. As of October 8, it had eight victims posted on its leak site, and its business model remains unconfirmed, with observers unsure whether it operates as a ransomware-as-a-service provider or as an independent operation.
One week before the T-Mobile listing, the gang published the data of 3,615 Trump Mobile users, including names, contact details, addresses, and orders.
Deutsche Telekom faces repeated claims
T-Mobile US is majority-owned by Deutsche Telekom, which holds a 53 percent stake and is Europe's largest telecommunications provider. T-Mobile US has approximately 142 million customers in the United States.
Deutsche Telekom and its subsidiaries have faced repeated hacker claims in recent years, which the company has denied. In 2024, Deutsche Telekom was one of dozens of companies posted on the LockBit ransomware leak site. In 2025, hackers claimed to have leaked 64 million records from T-Mobile, which T-Mobile said were not related to the company or its clients. In May, hackers claimed to have obtained a Deutsche Telekom dataset and put it up for sale, which the company denied as not real. Just one week before the T-Mobile threat, ransomware gang Safepay claimed to have breached Deutsche Telekom subsidiary T-Systems. T-Systems confirmed that the gang was pressuring it to pay a ransom but denied that any sensitive data had been exfiltrated, stating that attackers had only breached a small test environment.
Cybernews reached out to T-Mobile and is awaiting an official statement.
Sources: Cybernews
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.