The Trump Mobile Data Leak, revealed on May 20, 2026, exposes the mailing addresses, email addresses, and order numbers of thousands of customers. No response from the company to date.
A vulnerability that grants access to the entire customer base
The problem is serious. An anonymous security researcher discovered a vulnerability on the official website trumpmobile.com allowing free access to all customer data recorded during pre-orders of the T1 smartphone. Full names, mailing addresses, email addresses, phone numbers, and order details are accessible. According to unofficial information reported by several sources, an attacker could even browse the entire database and place fake orders through this same vulnerability.
The only good news for affected customers is that the banking information seem to be spared. Credit card numbers are reportedly not accessible through this vulnerability. Otherwise, the situation is concerning.
How the alert reached the public
The matter was brought to public attention by two popular YouTubers on May 20, 2026. Coffeezilla and penguinz0 (also known by the pseudonym MoistCr1TiKaL) both placed an order for the T1 out of curiosity, without particular support for the brand or the political figure associated with it. The anonymous researcher contacted them directly and provided them with their own personal data as proof of access.
"I know that because sadly I am one of those customers whose mailing address, email address, you know, everything short of credit card number is being leaked," Coffeezilla stated in a video published on YouTube. "Do not order on trumpmobile.com unless you're ready for your information to be leaked. It's basically that bad." (I know that because sadly I am one of those customers whose mailing address, email address, you know, everything short of credit card number is being leaked. Do not order on trumpmobile.com unless you’re ready for your information to be leaked. It's basically that bad.)
Penguinz0, for his part, indicated that the researcher had tried to contact Trump Mobile without success. "We were all met with radio silence," he stated in his own video. (“All of us have been met with radio silence.”) Neither the YouTubers nor the researcher have publicly detailed the exact exploit method for the vulnerability, precisely because it remains active and easily reproducible.
Sales figures that contradict official announcements
Beyond the data leak, the vulnerability reveals information that further embarrasses Trump Mobile on another front. By analyzing the order identifiers accessible in the exposed database, Coffeezilla estimates that the actual number of unique customers is around 10,000, for a total of approximately 30,000 orders. This figure contrasts sharply with the estimates that have circulated until now.
According to an estimate published by Yahoo Finance in 2025, approximately 590,000 pre-orders were reportedly registered, representing a collection of about $59 million at the $100 per order deposit rate. If the exposed data is reliable, the actual figure would represent barely 5% of the announced volume. Trump Mobile has not confirmed or denied these figures.
A phone already weakened by numerous controversies
The T1 smartphone has been mired in controversy since its launch. Announced as a device entirely manufactured in the United States, the phone now sports the wording “Designed with American values” and “Shaped by American innovation” in its marketing materials, according to a report by NBC News, whose journalists were able to handle the device about nine months after the initially planned delivery date.
Aesthetically, The Verge noted that the American flag integrated into the phone's design has only 11 stripes instead of the expected 13, although it's possible the “TRUMP MOBILE” logo was designed to represent the twelfth stripe. Several observers have also noted a striking resemblance to the HTC U24 Pro, a two-year-old model, suggesting it might be a rebranded device. As soon as pre-orders opened, the site had already caused problems: 404 Media reported that the order page displayed errors and charged incorrect amounts.
Trump Mobile remains silent in response to requests for comment
The security vulnerability is still open at the time of publication of this article. Trump Mobile has not responded to requests for comment from TechCrunch, nor to alerts sent by the researcher who discovered the vulnerability. No fix timeline has been publicly communicated.
For customers who have pre-ordered the T1, caution is advised. It is advisable to monitor any unusual activity related to the email and postal addresses used during the order, and to avoid placing new orders on the site until the vulnerability is fixed. This case illustrates a recurring problem in tech product launches associated with political or personal brands: aggressive communication about sales figures and industrial patriotism can mask serious operational shortcomings, not least of which is data security.




No comments! Be the first one.