// ARS TECHNICA — CYBERSECURITY
Trump Mobile hack and apparent lack of FCC authorization raise security alarms
After hack and data breach, senator asks why Trump Mobile lacks some FCC filings.
Trump Mobile apparently failed to obtain necessary authorizations to operate the international calling portion of its phone service, Sen. Maggie Hassan (D-N.H.) wrote in a letter to the company today.
Her letter said Trump Mobile also doesn’t appear to have submitted a required plan for fighting robocalls. Trump Mobile’s key business partner, Liberty Mobile Wireless, did make a robocall database filing, but it was not complete, Hassan said.
Hassan’s letter raised questions about Trump Mobile’s security related to a report that hackers stole personal data of 3,615 customers and Trump Mobile’s previous confirmation that a vendor it uses exposed customers’ personal data on the Internet. Hassan alleged that Trump Mobile failed to follow multiple FCC filing rules that are supposed to help ensure the security of mobile services.
“The apparent absence of authorization for Trump Mobile international services raises questions about who is providing or reselling the international telecommunications services advertised by Trump Mobile, the authority under which those services are being provided, and the company’s commitment to complying with requirements designed to safeguard national security,” Hassan told Trump Mobile CEO Patrick O’Brien.
Referring to the recent data breach, Hassan said it’s worrisome that a ransomware group “claimed that when it notified Trump Mobile of the breach, the company responded that ‘[w]e have no team to handle this.’” Trump Mobile also seems to lack a robust customer authentication process and offers “streamlined service activation that can make it easier for scammers to obtain US numbers,” Hassan wrote.
Trump Mobile, which has a trademark and name licensing deal with the Trump family, advertises that its customers can call more than 230 countries and territories. “Yet a search of the FCC’s International Communications Filing System suggests that Trump Mobile does not hold the necessary authorization for these services under Section 214 of the Communications Act of 1934,” wrote Hassan, the top Democrat on the US Congress Joint Economic Committee.
Hassan said the authorization process requires disclosure of foreign ownership so the FCC can assess potential national security risks. These FCC filings are required both for carriers that operate their own networks and Mobile Virtual Network Operators (MVNOs) like Trump Mobile, which resell other carriers’ mobile service, Hassan’s letter said.
Hassan’s letter cited a 2012 ruling against a different carrier, in which the FCC said “international telecommunications carriers that fail to obtain Section 214 authority may endanger important public interest considerations involving national security, law enforcement, foreign policy and trade policy.” She also cited the 2021 revocation of China Telecom Americas’ authorization, in which the FCC said that a carrier controlled by a foreign government could be used to “access, monitor, store, disrupt and/or misroute US communications” for the purpose of espionage.
Hassan asked questions about Trump Mobile’s ties to Liberty Mobile Wireless, an MVNO based in Florida. Trump Mobile officials told The Verge in February that Liberty Mobile is the “enabler” and “backbone” of Trump Mobile, and that Liberty Mobile handles much of Trump Mobile’s technical, legal, and financial operations.