Apps & Consumer
Trump Mobile confirms customer data exposure
Trump Mobile confirmed customer personal data was exposed to the open internet, attributing the incident to an unnamed third-party platform provider.
The Trump-branded phone maker Trump Mobile has confirmed that it exposed customers’ personal data to the open internet. The exposed information includes sensitive customer details such as names, email addresses, mailing addresses, cell numbers, and order identifiers. The company’s admission follows reports earlier this week indicating that Trump Mobile customers’ data was publicly accessible from the web. According to Chris Walker, a spokesperson for Trump Mobile, the security exposure was linked to an unnamed third-party platform provider. Walker stated that this external vendor supports “certain Trump Mobile operations,” though the company has declined to name the specific provider involved in the incident.
The timeline of the discovery highlights the role of external actors in identifying the vulnerability. On Wednesday, two YouTubers who had ordered the Trump Mobile phone, Coffeezilla and penguinz0, reported that a security researcher had alerted them that their personal information was exposed online. The two content creators stated that they subsequently tried to alert Trump Mobile of the exposure. This outreach occurred after the security researcher had also tried to contact the phone maker regarding the vulnerability, reportedly to no avail, prompting the creators to make their own attempts to reach the company.
In the wake of the public disclosures, Trump Mobile has defended its internal security systems. The company stated that there was no breach of Trump Mobile’s network, systems, or infrastructure. Walker told TechCrunch that the company is currently investigating the exposure, but noted that Trump Mobile has not found evidence that content or financial information was exposed to the open internet. This distinction emphasizes the company’s position that its core infrastructure remained secure despite the third-party exposure.
As the investigation continues, the company is weighing its next steps regarding customer communications. Walker stated that Trump Mobile is currently evaluating whether it needs to notify customers of the exposure of their personal data. The decision on whether to issue formal notifications remains pending as the company continues to assess the situation and determine the appropriate course of action for its affected users.
Why it matters
This incident underscores the security risks inherent in relying on third-party vendors for critical operations, as Trump Mobile navigates the fallout of exposing user information.