Back to news
Cybersecurity Alert
August 4, 2026 by EmailMeNow IT Consulting

Was Earthbound Holding Breached? Grapevine Retailer Faces N.D. Tex Litigation

Earthbound Holding LLC (Earthbound Trading) reported 1,866 Texans affected after a Dec 2025 network incident exposing employee SSNs. N.D. Tex In Re litigation; audits score earthboundtrading.com at 73%.

Source: Texas OAG · CourtListener

NewsData BreachTexasRetailClass ActionCybersecurity
Earthbound Holding LLC Grapevine retail data breach and Northern District of Texas lawsuits

Yes — Earthbound Holding LLC was breached. The Grapevine, Texas parent of lifestyle retailer Earthbound Trading Co. filed with the Texas Attorney General on March 16, 2026, reporting 1,866 Texas residents affected. Consumer notice went out by U.S. Mail.

Company and state AG notices describe unusual network activity on December 18, 2025, a completed impact review on March 6, 2026, and mail notices around March 12, 2026. National headcount in secondary reporting is about 6,766 (primarily current and former employees). Federal litigation is captioned In re Earthbound Holding, LLC Data Breach Litigation in the U.S. District Court for the Northern District of Texas (3:26-cv-01096, filed April 6, 2026).

We scanned earthboundtrading.com to assess email and domain security posture relevant to HR-notice spoofing.

What Happened

According to Texas OAG records, Maine AG materials, and CourtListener RECAP dockets:

  • December 18, 2025 — Unusual activity / unauthorized acquisition on Earthbound’s network.
  • March 6, 2026 — Impact review confirms personal information involved.
  • March 12, 2026 — Multi-state consumer notices (U.S. Mail); FBI notified per company statements.
  • March 16, 2026 — Texas OAG lists 1,866 Texans (names + SSNs).
  • April 6, 2026In Re docket 3:26-cv-01096 (N.D. Tex).

Breach Impact at a Glance

FieldDetail
EntityEarthbound Holding LLC / Earthbound Trading (earthboundtrading.com)
SectorSpecialty retail (lifestyle / home décor)
HQGrapevine, Texas
Texans affected1,866
National impact (reported)~6,766 (employees / former employees)
Consumer noticeYes (U.S. Mail)
Federal litigationIn re Earthbound Holding… 3:26-cv-01096 (N.D. Tex)

Data at Risk

Texas OAG records list exposed categories including:

  • Names of individuals
  • Social Security numbers

Secondary multi-state notices also reference addresses, government IDs, and dates of birth for some populations — treat those fields as reported in other jurisdictions, not as expanding the Texas OAG row beyond names + SSNs.

Illustration: specialty retailer employee SSN exposure after network intrusion

Employee SSN exposure drives tax-refund fraud, fake W-2 phishing, and spoofed “Earthbound HR / payroll” email.

Illustration: spoofed Earthbound HR payroll phishing after breach notices

Independent Cybersecurity Audit

We ran an EmailMeNow Cybersecurity Audit of earthboundtrading.com on August 4, 2026:

DomainOverallIdentityTransportWebsiteRisk
earthboundtrading.com73%65%15%87%Good

Key findings:

  • 73% overall (Good) — respectable for specialty retail, still below the 100% ideal when SSNs are in scope.
  • 65% Identity & Spoofing — room to tighten DMARC toward full enforcement.
  • 15% Transport Security — no effective MTA-STS enforcement; the same mail-path gap seen across many Texas OAG filers.
  • 87% Website Security — public storefront headers are comparatively strong.

Illustration: earthboundtrading.com audit with transport security gap

Audit link: earthboundtrading.com audit

Lookalike domains

A cybersquat scan of earthboundtrading.com found registered lookalikes earthboundtradin.com (omission) and earthboundtrading.co (TLD swap). earthboundtrading.biz / .net redirect to the brand site (likely owned). Prefer official notice channels — see Cybersquat Domain Monitoring.

Email blacklist check

MX/domain DNSBL check on August 4, 2026: clear on checked mail/domain lists (public DoH). Fastly/CDN web IPs showed informational SPFBL notes (not counted as mail reputation). Some Spamhaus/URIBL rows were unavailable via public resolvers — verify on check.spamhaus.org if needed.

Website stack probe — earthboundtrading.com

We checked what earthboundtrading.com publicly reveals about its website software on August 4, 2026:

What we checkedWhat we found
Website platformMagento (low confidence — version not exposed)
CMS freshnessDetected; no automated Magento version check in this probe yet
Certificate (HTTPS)Valid Let’s Encrypt certificate (~86 days remaining at check time)

Bottom line: a Magento storefront fingerprint is consistent with specialty e-commerce retail. Without a public version string we cannot score core freshness; treat this as a stack signal only — it does not prove how the December 2025 network incident occurred.

Priority Actions

If you received an Earthbound notice:

  • Enroll in official monitoring only via the letter; freeze credit if your SSN was listed.
  • Ignore unexpected W-2 / payroll “re-verification” emails unless verified by phone using a known store/HQ number.

For specialty retailers with employee PII:

  • Enforce DMARC + MTA-STS toward the 100% ideal before the next hiring season.
  • Keep HR/payroll files off the same segments that host public e-commerce tooling.

Run a free Instant Cybersecurity Audit at audit.emailmenow.com or contact EmailMeNow IT Consulting for retail email hardening and incident response planning.


Sources: Texas OAG — Data Security Breach Reports · CourtListener — In re Earthbound Holding, LLC Data Breach Litigation · Maine AG — Earthbound Holding notice · EmailMeNow audit — earthboundtrading.com