Trump Mobile
Incident posture
Linked entities
- Victim
- Trump Mobile
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A security researcher alerted a YouTuber that personal details submitted to Trump Mobile, including names, email addresses, mailing addresses and phone numbers, were exposed on the open web. The leak originated from a third‑party platform used by the company and was later patched after the vulnerability was disclosed. Trump Mobile confirmed the incident and said it was assessing whether to notify affected individuals.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Trump Mobile announced June 2025 as the T1 phone, a brand created by Eric and Donald Trump Jr., with the rollout delayed from the original schedule. In October 2025 a journalist from 404 Media reported unauthorized charges on their account after providing payment information for a $100 deposit. In May 2026 a security researcher contacted YouTuber Coffeezilla, informing him that his and other Trump Mobile customers’ data had been exposed on the open web, with the exception of his credit card details.
According to TechCrunch, the exposed data included names, email addresses, mailing addresses, phone numbers, and order identifiers. The leak originated from a third‑party platform contracted by Trump Mobile; the vendor was not publicly named. Trump Mobile’s spokesperson Chris Walker confirmed the leak to TechCrunch, while the company did not reply to emailed questions from Gizmodo. Coffeezilla reported that the security vulnerability had been patched, sharing a tweet on May 20, 2026 that noted the fix and thanked those who helped escalate the issue.
The leak made customers’ names, email addresses, mailing addresses, phone numbers, and order identifiers publicly accessible. Earlier, a journalist reported unauthorized charges on their account after providing a $100 deposit for the phone. After the vulnerability was patched, Trump Mobile indicated it was evaluating whether to notify customers of the exposure. The company has not issued a public notification as of the article’s date and did not respond to Gizmodo’s follow‑up questions.
Sources
Sources available to members: 1 source.