Trump Mobile faces FCC authorization questions after reported customer data incidents
Sen. Maggie Hassan asked Trump Mobile to explain alleged filing gaps and security issues; no FCC enforcement action has been announced.
By Dominic Okoye · Staff Writer
· 3 min read
Sen. Maggie Hassan, D-N.H., has asked Trump Mobile to explain apparent gaps in its Trump Mobile FCC authorization and anti-robocall filings after reports of customer-data exposures. In an October 8 letter to CEO Patrick O'Brien, Hassan sought answers on the company's international calling, customer verification, relationship with service partner Liberty Mobile Wireless, and response to two security incidents.
The letter is not an FCC finding of a violation, and no FCC enforcement action had been announced. Hassan requested a response by October 29.
Does Trump Mobile have FCC authorization for international calling?
Trump Mobile advertises calls to more than 230 countries and territories. Hassan wrote that a search of the FCC's International Communications Filing System suggested Trump Mobile did not hold the Section 214 authorization she said was required to provide those services.
She asked the company to identify any authorized underlying provider and document its arrangement. Trump Mobile has described itself as a mobile virtual network operator, meaning it resells service from larger carriers. Reporting has identified Florida-based Liberty Mobile Wireless as the company's service partner; Trump Mobile officials previously described Liberty as its technical, legal and financial backbone. Hassan asked whether Trump Mobile owns, operates or controls Liberty Mobile.
Section 214 filings can require disclosure of foreign ownership, allowing the FCC to assess national-security concerns, Hassan wrote. The available reporting does not establish whether another authorized carrier provides the international component on Trump Mobile's behalf.
Questions over robocall filings and customer verification
Hassan also said searches of the FCC's Robocall Mitigation Database found no filing under Trump Mobile or T1 Mobile LLC, its operating name. Liberty Mobile's latest filing appeared not to describe its customer-verification, or know-your-customer, procedures, according to the letter.
Those filings are intended to document efforts to prevent illegal robocalls and help providers identify customers who may be generating unlawful traffic. Incomplete or inaccurate submissions can result in fines, removal from the database, or orders requiring other providers to block a carrier's traffic. Hassan asked Trump Mobile to provide the filings or explain whether it considers another company responsible for them.
Two separate security incidents
In May, Trump Mobile acknowledged that a third-party vulnerability had made customer names, email addresses, mailing addresses, phone numbers and T1 preorder identifiers publicly accessible. The company said payment-card data, banking information and Social Security numbers were not affected, and said it had added safeguards.
Separately, the group calling itself BYOD claimed it had obtained and released data tied to 3,615 customers. The group told PCMag it compromised a Liberty Mobile employee's device using remote-access malware. That account and the claimed customer total have not been independently established in the available reporting, although PCMag reportedly confirmed that three people in the data had interacted with Trump Mobile.
Hassan asked whether customers were notified, whether the company verified the later claims, and whether the incidents stemmed from the same underlying breach. Trump Mobile, Liberty Mobile and the FCC were contacted for comment in reporting on the letter, but no response was reported.
This story draws on original reporting from Ars Technica.