Trump Mobile Data Breach Exposes eSIM QR Codes and Customer PII

Published: 24 September 2026
Other Commercial data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: Not Publicly Disclosed

A threat actor group called EndZone claims it breached Trump Mobile, a mobile carrier tied to the Trump Organization brand, and stole eSIM QR codes along with customer personal information. Trump Mobile has not publicly confirmed the claim. Affected or concerned customers should contact their carrier about SIM-swap protections and monitor their credit reports for suspicious activity right away.

CompanyTrump Mobile
IndustryOther Commercial
Data Types ExposedeSIM QR Codes, Customer Personal Information, Mobile Account Details
People AffectedNot Publicly Disclosed
Attack MethodExtortion/Data Theft Claim
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Trump Mobile Data Breach?

A threat actor group known as EndZone has claimed responsibility for a data breach affecting Trump Mobile. Trump Mobile is a mobile virtual network operator that licenses its brand from the Trump Organization. According to the claim, the attackers accessed customer data, including eSIM QR codes and other personal information.

The exact timeline of the alleged intrusion has not been publicly disclosed. As a result, it remains unclear when unauthorized access to the network may have first occurred. EndZone posted its claims to a leak site, listing Trump Mobile as a victim alongside details about the company’s reported user base.

Because this incident stems from a threat actor’s own claim, Trump Mobile has not publicly confirmed the breach. No independent forensic report has been released to verify the scope of the intrusion. Therefore, many details, including how the attackers gained access, remain unknown at this time.

Readers searching for information on the Trump Mobile data breach should understand that this situation is still developing. Additional facts may emerge as the investigation, if one is conducted, moves forward. In the meantime, the claim itself provides the only public information available.

Who was affected?

The population affected by this alleged breach includes Trump Mobile customers. Because the service is a consumer mobile plan, affected individuals are likely everyday phone subscribers rather than business accounts. However, this has not been confirmed by the company.

The number of affected individuals has not been publicly disclosed. The threat actor’s post referenced a customer base described only in general terms. Consequently, this article does not state a specific figure for people impacted, since no verified number exists.

Given that this is a US-based mobile carrier, affected customers are most likely located within the United States. There is currently no indication that minors were specifically targeted. Still, anyone who has ever signed up for Trump Mobile service should treat this claim seriously.

What Information Was Potentially Exposed?

The threat actor’s claim specifically references eSIM QR codes along with general customer personal information. eSIM QR codes are particularly sensitive because they can be used to activate a mobile line on another device. In addition, any accompanying personal details could compound the risk to affected customers.

  • eSIM activation QR codes
  • Customer personal identifiable information (PII)
  • Mobile account details potentially linked to the above

If accurate, this combination of data could allow bad actors to attempt SIM-swapping style fraud. For example, a stolen eSIM QR code could theoretically let someone impersonate a customer’s phone line. This is especially concerning because phone numbers are often used for two-factor authentication on banking and email accounts.

Beyond SIM-related risks, exposed personal information can also fuel phishing attempts and identity theft schemes. Criminals frequently combine small pieces of personal data from multiple sources to build convincing scams. Because of this, even seemingly minor exposed details deserve attention from affected customers.

What is the company doing?

At this time, Trump Mobile has not publicly confirmed the breach claimed by EndZone. No statement describing an investigation, remediation steps, or customer notifications has been made available. As a result, this article cannot state that any specific response has taken place.

Because the source of this report is the threat actor’s own leak site listing, readers should treat the underlying claims with appropriate caution. It is possible that further details, including any official company statement, will surface later. Until then, affected individuals should rely on their own protective steps rather than wait for confirmation.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals should check their credit reports regularly for unfamiliar accounts or inquiries. You can request a free copy from each of the three major credit bureaus through AnnualCreditReport.com. Reviewing these reports often helps catch fraudulent activity early.

In addition, consider spacing out requests across the year so you always have a recent report on hand. This means checking Equifax, Experian, and TransUnion at different times. If you notice anything unusual, dispute it with the bureau immediately.

Watch for Phishing Attempts

Because personal information may have been exposed, affected customers should be alert to phishing emails, texts, and calls. Scammers often use leaked data to make their messages seem more legitimate. For instance, they may reference your name or account details to gain trust.

As a result, never click links or share verification codes from unexpected messages. Instead, contact your carrier or bank directly using a known phone number. This extra step can prevent a scammer from hijacking your accounts.

Protect Against SIM-Swap Fraud

Since eSIM QR codes were reportedly involved, affected individuals should contact their mobile carrier to ask about extra account protections. Many carriers offer a PIN or passcode requirement before any SIM or eSIM changes can be made. This step can help block unauthorized line transfers.

Furthermore, consider moving away from SMS-based two-factor authentication where possible. Instead, use an authentication app or hardware security key for sensitive accounts. This reduces the risk if someone manages to take control of your phone number.

Consider a Fraud Alert or Credit Freeze

Because personal information may be involved, placing a fraud alert or credit freeze can add another layer of protection. A fraud alert requires lenders to verify your identity before opening new credit. A credit freeze goes further by blocking most new account openings entirely.

You can set up either option directly with the credit bureaus at no cost. Although a freeze requires you to lift it temporarily when applying for credit, it offers stronger protection overall. Given the uncertainty around this incident, this precaution is a reasonable step to take now.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

Check other recent data breach notifications →