The Trump Mobile data leak is now official. The operator acknowledged on May 22, 2026, that its customers' names, addresses, phone numbers, and emails were freely accessible online.
What Trump Mobile Admitted
The confirmation came from Chris Walker, the company's spokesperson, in a statement given to TechCrunch on May 22, 2026. The exposed data includes customers' full names, their email addresses, their postal addresses, their phone numbers, and their order credentials, all accessible on the open internet. The company specifies that no financial data was compromised and that there was no intrusion into its own systems or network infrastructure.
Walker attributed the exposure to a third-party provider supporting "certain Trump Mobile operations," without naming the vendor. This vagueness leaves the question of the chain of responsibility entirely open. Even more concerning: Trump Mobile is still evaluating whether or not to notify the customers affected by this exposure of their personal data.
How the Breach Was Revealed to the Public
The alert did not come from the company itself. It was YouTubers Coffeezilla and penguinz0, both customers who had pre-ordered the T1 phone in gold, who were contacted by a researcher who discovered the data exposed online. This researcher had initially tried to report the vulnerability directly to Trump Mobile, without success.
"Coffeezilla, penguinz0, and myself contacted Trump Mobile through every means possible to alert them and allow them to fix the issue, as this is a major vulnerability. We received no response," stated penguinz0. (We've all been met with radio silence.)
Coffeezilla, whose real name is Stephen Findeisen and who is known for his investigations into cryptocurrency scams, personally verified the vulnerability after the researcher provided him with excerpts of his own data as proof. "Everything short of a credit card number is being leaked," Coffeezilla stated in his video. (Everything short of a credit card number is being leaked.)
A Fixed Flaw, But Lingering Doubts
According to PCMag, the vulnerability had been fixed as early as May 20, 2026. Coffeezilla himself confirmed in a pinned comment on YouTube that the data was no longer accessible. However, the researcher who originally discovered it warned that others had already replicated the exploit "quite easily" before the fix. This observation raises serious questions about the possibility that the data is already circulating off-site.
Both content creators also raised broader questions about the overall security of Trump Mobile. The company offers a full phone service, which involves storing particularly sensitive data: browsing history, call logs, and location data.
Sales Figures Far Below Announcements
The data exposure had an unexpected effect: it allowed for the verification of Trump Mobile's actual sales figures, which turn out to be very far from those publicly communicated. While Trump Mobile had been widely presented as having collected approximately 590,000 pre-orders for its T1 phone, representing about $59 million in deposits, analysis of the exposed database actually reveals around 10,000 unique customers and 30,000 orders in total, or about 5% of the figures that had circulated in the media.
An Associated Press spokesperson confirmed that its original articles did not contain this figure of 590,000 pre-orders, which was nevertheless widely reported by numerous media outlets and even by artificial intelligence tools. This radical downward revision adds to the already long list of controversies surrounding the company since its launch.
Political Pressure Intensifies
Senator Mark Warner, vice-chairman of the Senate Intelligence Committee, sent a detailed letter to Trump Mobile CEO Patrick O'Brien after the vulnerability was revealed, setting a deadline of May 25, 2026, for him to answer 14 specific questions. These questions concern, among other things, the manufacturing of the phone and the company's security practices. The T1 phone was initially presented as being manufactured in the United States, a promise that has since disappeared from marketing materials, replaced by a phrase indicating that the device was "designed with American values in mind."
The delivery schedule has also been a source of ongoing tension. Announced for August 2025, the T1 phone was repeatedly postponed, to November, then December, and then 2026, before the release date was removed from the website. Trump Mobile announced in early May 2026 that shipments had finally begun.
This case illustrates a structural problem that goes beyond a simple technical flaw: a company that has not responded to security alerts, is still evaluating whether to notify its own customers, and whose announced figures do not stand up to scrutiny of the actual data. Customers whose information has been exposed are advised to monitor their accounts for any suspicious emails, calls, or SMS messages, and to immediately enable two-factor authentication on their online services.




No comments! Be the first one.