Back to news
Cybersecurity Alert
August 4, 2026 by EmailMeNow IT Consulting

Was Mobilelink Breached? Cricket Retailer Faces S.D. Tex Consolidation

Master Mobilelink / Mobily (Mobilelink) reported 12,201 Texans affected after a late-2025 incident. Consolidated S.D. Tex suits under 4:26-cv-02565; audits score mobilelinkusa.com at 84% with 15% transport.

Source: Texas OAG · CourtListener

NewsData BreachTexasRetailTelecomClass ActionCybersecurity
Mobilelink Cricket Wireless retailer data breach and Texas federal lawsuits

Yes — Mobilelink was breached. Master Mobilelink LLC and Mobily LLC, doing business as Mobilelink — a large authorized Cricket Wireless retailer headquartered in Sugar Land, Texas — filed with the Texas Attorney General on March 30, 2026, reporting 12,201 Texas residents affected. Consumer notice went out by U.S. Mail.

Company notices state discovery on February 26, 2026 that personal information may have been in data acquired without authorization during a recent incident (press accounts also reference late-2025 intrusion activity and DragonForce leak-site claims — treat actor claims as unverified until independently corroborated). Multiple consumer suits in the U.S. District Court for the Southern District of Texas are consolidated under Dudsic v. Master MobileLink LLC (4:26-cv-02565, filed March 31, 2026).

We scanned mobilelinkusa.com to assess email and domain security posture relevant to retail-notice spoofing.

What Happened

According to Texas OAG records, sample consumer notices, and CourtListener RECAP dockets:

  • Late 2025 — Unauthorized acquisition / intrusion window reported in secondary accounts (some cite ~December 2, 2025 DragonForce claims — unverified).
  • February 26, 2026 — Mobilelink discovers personal information may be in acquired data.
  • March 30, 2026 — Texas OAG lists 12,201 Texans; U.S. Mail notices.
  • March 31–April 1, 2026 — Federal suits filed; member cases directed to lead 4:26-cv-02565.

Breach Impact at a Glance

FieldDetail
EntityMaster Mobilelink LLC & Mobily LLC d/b/a Mobilelink (mobilelinkusa.com)
SectorWireless retail (Cricket authorized dealer; 450+ stores reported)
HQSugar Land, Texas
Texans affected12,201
Consumer noticeYes (U.S. Mail; IDX monitoring offered in sample notices)
Federal litigationDudsic v. Master MobileLink 4:26-cv-02565 (S.D. Tex lead)
Leak-site claimDragonForce (treat as unverified claim)

Data at Risk

Texas OAG records list exposed categories including:

  • Names
  • Social Security numbers
  • Financial account / payment card information
  • Dates of birth

Illustration: prepaid wireless retailer customer SSN and payment data exposure

Retail wireless customers are high-value targets for SIM-swap, account-takeover, and fake “Cricket / Mobilelink refund” phishing after SSN exposure.

Illustration: Mobilelink breach notice window and SIM-swap phishing risk

Independent Cybersecurity Audit

We ran an EmailMeNow Cybersecurity Audit of mobilelinkusa.com on August 4, 2026:

DomainOverallIdentityTransportWebsiteRisk
mobilelinkusa.com84%90%15%92%Good

Key findings:

  • 84% overall (Good) — stronger public posture than many retail peers, but still below the 100% ideal.
  • 90% Identity & Spoofing — solid DMARC-related controls reduce (but do not eliminate) spoofed notice risk.
  • 15% Transport Security — the recurring gap: without MTA-STS mode=enforce, mail-path downgrade remains possible.
  • 92% Website Security — public headers are comparatively strong.

Illustration: mobilelinkusa.com audit with strong identity but weak transport

Audit link: mobilelinkusa.com audit

Lookalike domains

A cybersquat scan of mobilelinkusa.com found mobillinkusa.com with BEC staging signals (NS + MX, no useful website A/AAAA) plus other registered lookalikes (mobilelinksusa.com, mobilelinkus.com, moblielinkusa.com). High risk for fake refund / ACH threads during the notice window — see Cybersquat Domain Monitoring.

Email blacklist check

MX/domain DNSBL check on August 4, 2026: clear on checked mail/domain lists (public DoH). Some Spamhaus/URIBL rows were unavailable via public resolvers — verify on check.spamhaus.org if deliverability is in dispute.

Website stack probe — mobilelinkusa.com

We checked what mobilelinkusa.com publicly reveals about its website software on August 4, 2026:

What we checkedWhat we found
Website platformUndetected from passive homepage fingerprints (low confidence)
Certificate (HTTPS)Valid GlobalSign certificate (~149 days remaining at check time)

Bottom line: the storefront did not advertise a clear CMS/version to the probe. Keep focus on the email path (15% transport) and SIM-swap / refund phishing risk while notices circulate — stack opacity is not the same as breach root cause.

Priority Actions

If you received a Mobilelink notice:

  • Enroll in official IDX / monitoring only via the letter’s URL or phone number.
  • Watch carrier accounts for unauthorized SIM changes; enable carrier-level account PIN / port-out protection.

For multi-store wireless retailers:

  • Close the 15% transport gap with MTA-STS enforcement and TLS-RPT.
  • Segment store POS / CRM data from corporate email tenants after any DragonForce-class claim wave.

Run a free Instant Cybersecurity Audit at audit.emailmenow.com or contact EmailMeNow IT Consulting for retail email hardening and incident response planning.


Sources: Texas OAG — Data Security Breach Reports · CourtListener — Dudsic v. Master MobileLink LLC · EmailMeNow audit — mobilelinkusa.com