Based Apparel, the merchandise website associated with FBI Director Kash Patel, was taken offline after a compromise that allegedly attempted to trick visitors into installing malware. Reporting indicated the attack was designed to deliver infostealer malware capable of stealing user credentials, and the issue was first flagged by a user on X before a security researcher analyzed the activity. As of Friday morning, the site remained offline while the incident was being addressed.
The compromise was reported alongside a separate security issue affecting Trump Mobile, which said customer information was exposed after a researcher alerted YouTubers who had purchased the company’s phone. The exposed data reportedly included names, email addresses, mailing addresses, and phone numbers, underscoring the cyber risk facing consumer-facing platforms tied to prominent political figures and brands.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
In a separate incident noted in the reporting, Trump Mobile confirmed that customer data including names, email addresses, mailing addresses, and phone numbers had been exposed. The exposure was identified after a researcher alerted YouTubers who had purchased the company's phone.
Following reports of the cyberattack, Based Apparel was taken offline on Friday. Reports said the site remained offline as of Friday morning.
Analysis of the Based Apparel incident revealed attackers used a fake Cloudflare verification prompt on a Kash Foundation merchandise page to trick macOS users into running a malicious terminal command. The payload reportedly installed an infostealer capable of stealing cryptocurrency wallet data, session tokens, Keychain contents, and browser-stored credentials.
The merchandise website Based Apparel, associated with FBI Director Kash Patel, was reportedly hacked in an attempt to infect visitors with infostealer malware designed to steal credentials. The compromise was first surfaced by a user on X and then analyzed by a security researcher.
In March 2026, Kash Patel disclosed that his personal Gmail account had been hacked. Reporting said the intrusion was widely believed to be linked to Iranian intelligence.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
9 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcesecurityaffairs.com
Open sourceteiss.co.uk
Open sourcescworld.com
Open sourcesan.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcepcmag.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.