NEWS
Trump Mobile Leak Surfaces 27,000 Customers, Not 590,000
Trump Mobile confirmed on Friday that a third-party platform serving its website exposed customer names, addresses, email addresses and phone numbers for roughly 27,000 buyers of the gold-colored T1 smartphone, after a self-described “nerd between jobs” pulled records out of an unprotected API endpoint and tipped two YouTube creators with a combined audience above 24 million. The patch went up only after Stephen Findeisen, who streams as Coffeezilla, and Charles White, who streams as penguinz0, published their videos on May 19.
That count carries a second story. Trump Mobile has spent eleven months trading on the claim that roughly 590,000 people paid a $100 refundable deposit for the device. The leaked dataset, as described by the researcher who pulled it and the creators who reviewed it, accounts for a small fraction of that figure.
What Trump Mobile Confirmed on Friday
The company gave its first on-record acknowledgement on May 22, three days after the YouTube videos went live and roughly five days after the researcher first attempted contact. A spokesperson said Trump Mobile was investigating, then drew a tight perimeter around the disclosure.
At this time, the impacted information appears to be limited to certain customer details, including names, email addresses, mailing addresses, order identifiers and mobile phone numbers. The incident does not appear to involve Trump Mobile payment card information, banking information, Social Security numbers, call records, text messages, or other highly sensitive financial data.
The spokesperson also said Trump Mobile’s “systems, infrastructure, and network were not compromised,” and pointed at a third-party platform provider that the company declined to name. That distinction matters legally. It matters less practically. A customer whose mailing address now sits in a scraped dump cares only that the address is out, not which contractor’s API let it walk.
Findeisen identified himself as one of the affected customers in his post on the voidzilla channel and said he had been one of the people trying to reach the company. White, in a separate video, said the researcher, Findeisen and he had each tried multiple channels before going public. “All of us have been met with radio silence,” White said.

How a POST Request Looped Through Customer Records
The exploit was not subtle. A researcher who identified himself only as “Louis” told gHacks Tech News he found the flaw by inspecting browser console traffic, then sending repeated HTTP POST requests to an endpoint that returned ten customer records per call. Each record carried a sequential customer number. Louis wrote a loop, walked the range, and pulled roughly 5,000 records in an hour before stopping. He estimated the full exposed pool at more than 27,000 customers.
He described the bug as very low hanging fruit. That language matters. Sophisticated controls are what get bypassed in serious breaches. An unauthenticated, paginated, sequentially keyed API endpoint is a failure of the basics that any production security review would catch on the first pass.
The categories of leaked data, drawn from screenshots reviewed by the researcher and the YouTube creators:
- Full names tied to billing and shipping addresses
- Primary and secondary mailing addresses
- Email addresses used at checkout
- Mobile phone numbers, including the line the customer intended to port to Trump Mobile
- Internal customer and account numbers
- Enrollment identifiers, including pre-order numbers
- A flag indicating whether the order was placed by phone or online
What is missing from that list is also informative. Payment card numbers, banking credentials and Social Security numbers were not in the dataset, consistent with the company’s statement. That places the exposed endpoint in the front-of-house order-management layer, not the payment processor. It is the cheap part of the stack, the part a brand-licensing operation is most likely to hand to a small vendor with a thin security budget.
The Leaked Headcount Versus the Preorder Story
Trump Mobile launched in June 2025 with a $100 refundable deposit on the T1 device. By late summer, social-media posts and friendly outlets were citing 600,000 preorders. A figure of 590,000 buyers, representing roughly $59 million in deposits, hardened over the next few months into a load-bearing piece of the brand’s marketing.
The company never confirmed that number. The leaked dataset is the first piece of independently observable evidence about the actual customer book, and it lands well short of the headline.
| Metric | Public narrative | Coffeezilla’s review | Researcher’s estimate |
|---|---|---|---|
| Unique customers | ~590,000 | ~10,000 | ~27,000 |
| Total orders | not disclosed | ~30,000 | not specified |
| Implied deposits at $100 | ~$59 million | ~$1 million | ~$2.7 million |
| Period covered | June 2025 to May 2026 | through May 2026 | through May 2026 |
Two caveats belong on the file. The leaked endpoint may not represent the complete customer base; it could be a snapshot, a region, or a subset of order pathways. And Louis stopped pulling at 5,000 records, projecting the rest. Both qualifications still leave a gap of roughly twenty times between the public claim and the observable book. That gap is now the most interesting number in the story.
Liberty Mobile Wireless and the Stack Behind the Brand
The third-party platform Trump Mobile pointed at is a useful piece of misdirection. The structural story is that the brand sitting behind a flag-emblazoned smartphone is a licensed name on top of an existing carrier, which itself is a virtual operator riding T-Mobile’s radio network. The data leak surfaced one of the three layers. The other two are worth naming.
The MVNO Plumbing
Trump Mobile’s terms of use disclose that service is powered by Liberty Mobile Wireless LLC, a Florida-based mobile virtual network operator that resells T-Mobile USA capacity. T-Mobile collects from Liberty Mobile Wireless. Liberty collects from the licensee. The licensee markets the brand. None of those three parties built the API endpoint that leaked. That endpoint was written for, or by, the e-commerce contractor behind trumpmobile.com, the entity Trump Mobile is now calling a third-party platform provider.
The Brand-License Layer
The Trump Organization licensed the name to T1 Mobile, an operating entity launched in June 2025 by Donald Trump Jr. and Eric Trump. The licensor takes royalties. It does not run the network, write the storefront code, or hold the customer-record database. When a leak happens at the storefront, every party in the chain can credibly say its own systems were not compromised. The data still ends up scraped, and the customer still received a marketing email from a brand called Trump Mobile.
Who Has to Notify Whom
That diffusion of responsibility is the part regulators are likely to test. Under federal communications rules, the carrier is the entity holding the breach-notification obligation. Liberty Mobile Wireless is the carrier of record on these lines. Whether the notification clock falls to Liberty, to T1 Mobile, or to both, none of the three companies named had publicly confirmed which entity was filing as of Wednesday.
The FCC Clock Trump Mobile Is Now Running
In December 2023 the Federal Communications Commission overhauled its breach rules for telecommunications carriers in its updated data breach notification order. The new framework took effect in March 2024 and was upheld by the Sixth Circuit appeals court in 2025. The rule is codified at 47 CFR 64.2011. Liberty Mobile Wireless, as the underlying carrier, sits squarely inside it.
The mechanics for a breach touching tens of thousands of customers are tight:
- The carrier must notify the FCC, the FBI and the Secret Service via the central reporting facility, in no case more than seven business days after a reasonable determination that a breach occurred.
- If 500 or more customers are affected, the seven-day clock applies regardless of whether harm is judged likely.
- Customer notification must follow agency notification without unreasonable delay, and in no case more than 30 days after the breach determination.
- Annual summary reports cover sub-500-customer events; the Trump Mobile incident is past that threshold by two orders of magnitude.
Trump Mobile said on Friday it was “evaluating whether customer notification was required.” The text of the rule does not leave much room for evaluation when the affected count is in five figures and the dataset includes customer-name and mobile-number pairs, the exact combination the rule was rewritten to cover. As of Wednesday no breach notice linked to Liberty Mobile Wireless or T1 Mobile had appeared on the commission’s public docket.
A Gold Phone, an HTC Donor Body, and a Trust Problem
The T1 device is a gold-shelled version of HTC’s U24 Pro from 2024. The American flag stamped on the rear has eleven stripes instead of thirteen. Truth Social ships pre-installed. Trump Mobile has quietly retired the “Made in the USA” language that anchored its launch, replacing it with phrases like “brought to life in the United States” and, on the current site, “designed with American values in mind.” The phone retails for $499, the plan runs $47.45 per month before tax, and the device is now reaching customers’ hands roughly nine months later than the August 2025 ship window the company first published under its official preorder deposit terms.
A buyer who paid the deposit eleven months ago, opened a gold smartphone last week, then learned over the weekend that the name on the shipping label was scraped off a poorly built API, has reasons to be done with the brand that have nothing to do with politics. Refunds are constrained by the deposit fine print. The company says deliveries continue over the next several weeks. If the FCC sends a letter, Liberty Mobile Wireless will receive it. If a plaintiff files a class action, the licensee will receive the complaint. The question hanging over the licensee is whether the customers most loyal to the brand read this week’s story and feel rewarded for the wait, or read it and quietly cancel.
-
AI3 weeks agoFable 5 and Mythos 5 Return as US Lifts Anthropic Export Controls
-
AI1 month agoSpaceX’s Google Deal Turns a Rocket Company Into a Cloud Landlord
-
APPS1 month agoDGO App Brings Rs 549 Mobile Pass for FIFA World Cup 2026 in Nepal
-
CRYPTO1 month agoXPL Rallies 30% Ahead of Plasma One Card Tier Launch
-
GAMING4 weeks agoCD Projekt Red Co-CEO: Redemption Arc Isn’t Done, Witcher 4 in 2027
-
NEWS1 month agoGoogle Search Profiles Build a Follow Graph Inside Discover
-
AI4 weeks agoOracle Cuts 21,000 Jobs in a Year, Cites AI in 10-K Filing
-
AI1 month agoMoonshot AI Targets $30 Billion in China’s Fastest AI Funding Sprint
