Trump Mobile confirmed that customer personal data was exposed on the public internet after researchers and customers found that preorder and order information could be retrieved through an unprotected API. Reports said the flaw allowed simple HTTP POST requests to return records in batches, exposing names, email addresses, mailing addresses, cell phone numbers, order identifiers, and in some cases customer or account numbers and enrollment IDs. Multiple outlets reported that more than 27,000 customers were affected, with leaked order identifiers suggesting roughly 30,000 phone orders tied to the T1 smartphone launch.
The issue was first publicized after YouTubers Coffeezilla and penguinz0 said a researcher alerted them that their own Trump Mobile order details were accessible online, and the researcher reportedly failed to get a response from the company before the exposure became public. Trump Mobile said it found no evidence that payment card data, banking information, Social Security numbers, call records, text messages, or message content were exposed, and attributed the incident to an unnamed third-party platform provider rather than a compromise of its own systems. The company said the flaw has been addressed and an investigation is ongoing, but reports said it was still evaluating whether affected customers would be notified.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
By May 26, 2026, reporting cited in coverage said 27,224 people who submitted information through the Trump Mobile pre-order form were affected. The figure refined earlier estimates that the exposed order records were in the tens of thousands.
A researcher identified as "Louis" found that Trump Mobile customer order data was publicly accessible via API endpoints and said he was unable to get the company to remediate the issue. The exposed data reportedly included names, email addresses, mailing addresses, phone numbers, and order-related identifiers.
In its confirmation, Trump Mobile said the incident appeared tied to an unnamed third-party platform provider supporting certain operations and stated there was no breach of its own network, systems, or infrastructure. The company also said it was investigating and evaluating whether affected customers needed notification.
On May 22, 2026, Trump Mobile confirmed that customer personal data had been exposed on the public internet. The company said the exposed information included names, email addresses, mailing addresses, cell phone numbers, and order identifiers, and that it had found no evidence financial information was exposed.
After ordering the Trump Mobile T1 phone, YouTubers Coffeezilla and penguinz0 said a researcher showed them that their personal information was accessible online. Their disclosures helped bring public attention to the exposure.
On May 20, 2026, TechCrunch reported that Trump Mobile was exposing customer data and that the issue was still unpatched at the time of publication. The report said Trump Mobile did not respond to requests for comment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
11 references tracked. Mallory keeps watching after this page renders.
techdirt.com
Open sourceboingboing.net
Open sourceboingboing.net
Open sourceghacks.net
Open sourceupguard.com
Open sourcescworld.com
Open sourcepcmag.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.