The Trump Mobile data leak is now official. The operator acknowledged on May 22, 2026, that its customers' names, addresses, phone numbers, and emails were freely accessible online.
What Trump Mobile admitted
The confirmation came from Chris Walker, a company spokesperson, in a statement to TechCrunch on May 22, 2026. The exposed data includes customers' full names, email addresses, physical addresses, phone numbers, and order identifiers, all accessible on the open internet. The company states that no financial data was compromised and there was no intrusion into its own systems or network infrastructure.
Walker attributed the exposure to a third-party provider supporting "certain Trump Mobile operations," without naming the vendor. This vagueness leaves the question of the chain of responsibility entirely open. More concerningly, Trump Mobile is still evaluating whether or not to notify customers affected by this exposure of their personal data.
How the flaw was revealed to the public
The alert did not come from the company itself. YouTubers Coffeezilla and penguinz0, both customers who had pre-ordered the T1 phone, were contacted by a researcher who discovered the exposed data online. This researcher had initially tried to report the vulnerability directly to Trump Mobile, without success.
"Coffeezilla, penguinz0, and myself contacted Trump Mobile through every means possible to alert them and allow them to fix the problem, as it's a major flaw. We received no response," stated penguinz0. (We've all been met with radio silence.)
Coffeezilla, whose real name is Stephen Findeisen and who is known for his investigations into cryptocurrency scams, personally verified the flaw after the researcher provided him with excerpts of his own data as proof. "Everything short of a credit card number is being leaked," Coffeezilla stated in his video. (Everything short of a credit card number is being leaked.)
A flaw corrected, but doubts remain
According to PCMag, the vulnerability had been fixed as early as May 20, 2026. Coffeezilla himself confirmed in a pinned comment on YouTube that the data was no longer accessible. However, the researcher who originally discovered it warned that others had already replicated the exploit "quite easily" before the fix. This observation raises serious questions about the possibility that the data is already circulating outside the site.
Both content creators also raised broader questions about Trump Mobile's overall security. The company offers a full phone service, which involves storing particularly sensitive data: browsing history, call logs, and location data.
Sales figures much lower than announced
The data exposure had an unexpected effect: it allowed for verification of Trump Mobile's actual sales figures, which turn out to be very far from those publicly communicated. While Trump Mobile had been widely presented as having collected approximately 590,000 pre-orders for its T1 phone, representing about $59 million in deposits, analysis of the exposed database actually reveals around 10,000 unique customers and 30,000 orders in total, or about 5% of the figures that had circulated in the media.
An Associated Press spokesperson confirmed that its original articles did not contain the figure of 590,000 pre-orders, yet this figure was widely reported by numerous media outlets and even by artificial intelligence tools. This radical downward revision adds to the already long list of controversies surrounding the company since its launch.
Political pressure intensifies
Senator Mark Warner, vice-chairman of the Senate Intelligence Committee, sent a detailed letter to Trump Mobile CEO Patrick O'Brien after the flaw was revealed, setting a deadline of May 25, 2026, for him to answer 14 specific questions. These questions concern, among other things, the manufacturing of the phone and the company's security practices. The T1 phone was initially presented as being manufactured in the United States, a promise that has since disappeared from marketing materials, replaced by a phrase indicating that the device was "designed with American values in mind."
The delivery schedule was also a source of ongoing tension. Announced for August 2025, the T1 phone was repeatedly postponed, to November, then December, then 2026, before the release date was removed from the website. Trump Mobile announced in early May 2026 that shipments had finally begun.
This case illustrates a structural problem that goes beyond a simple technical flaw: a company that has not responded to security alerts, which is still evaluating whether to notify its own customers, and whose announced figures do not stand up to scrutiny of the actual data. Customers whose information has been exposed are invited to monitor their accounts for any suspicious emails, calls, or SMS messages, and to immediately enable two-factor authentication on their online services.


No comments yet — start the discussion!