Four Texas organizations with confirmed AG notices and active federal data-breach class actions sit on the same scoreboard this week: Gulshan Management Services, the College of Health Care Professions (Empowerment Schools), Mobilelink, and Earthbound Holding. Dedicated deep-dives already cover each case — this post is the comparative audit / MFA / lookalike rollup, not a rehash of any single lawsuit.
We re-confirmed the lead dockets on CourtListener, ran fresh EmailMeNow domain audits (100% is the ideal), probed website stacks, checked mail/domain blacklists, scanned cybersquat lookalikes, and reviewed public docs for YubiKey / FIDO and open Google Authenticator–style TOTP.

Defendants at a glance
Texan impact figures are from Texas OAG breach reports. Docket links point at the lead / In Re case — not every member filing.
| Organization | Texans | Lead docket (filed) | Domain |
|---|---|---|---|
| Gulshan Management Services | 128,652 | S.D. Tex In Re 4:26-cv-00200 (Jan 12, 2026) | gulshanenterprises.com |
| CHCP / Empowerment Schools | 68,927 | S.D. Tex 4:26-cv-01747 (Mar 3, 2026) | chcp.edu |
| Mobilelink (Master MobileLink) | 12,201 | S.D. Tex lead 4:26-cv-02565 (Mar 31, 2026) | mobilelinkusa.com |
| Earthbound Holding | 1,866 | N.D. Tex In Re 3:26-cv-01096 (Apr 6, 2026) | earthboundtrading.com |
Combined Texas residents in notices: ~211,646. Sector mix: convenience retail (Qilin), healthcare education, wireless retail, specialty retail.
Independent cybersecurity audits
EmailMeNow audits on August 4, 2026. 100% is the ideal overall score — 0 of 4 reached it. Scores measure public identity / transport / website posture, not whether a jury has ruled on the underlying breach claims.
| Organization | Domain | Overall | Identity | Transport | Website |
|---|---|---|---|---|---|
| Mobilelink | mobilelinkusa.com | 84% | 90% | 15% | 92% |
| Earthbound Holding | earthboundtrading.com | 73% | 65% | 15% | 87% |
| CHCP / Empowerment | chcp.edu | 60% | 70% | 15% | 37% |
| Gulshan Management | gulshanenterprises.com | 43% | 10% | 15% | 62% |

Patterns:
- Transport = 15% on all four — none show effective MTA-STS
mode=enforce. Spoofed “breach notice / credit monitoring” mail stays easy to deliver during litigation headlines. - Strongest overall: Mobilelink 84% (still short of 100%). Weakest: Gulshan 43% with 10% identity — high spoofing risk for Handi Stop / Gulshan-branded mail.
- CHCP leads identity among the lower half (70%) but lags website hardening (37%).
Audit links: mobilelinkusa.com · earthboundtrading.com · chcp.edu · gulshanenterprises.com
MFA: YubiKey & Google Authenticator
Public consumer / student documentation only. Grade: Fail = SMS/voice/email OTP or password-only with no stronger factor documented; Partial = proprietary soft token / push without open TOTP or YubiKey; Pass = open TOTP; Strong = FIDO/YubiKey; Unevaluated = no useful public MFA docs.
| Organization | YubiKey / FIDO | Open TOTP | Grade |
|---|---|---|---|
| Gulshan (consumer) | Not documented | Not documented | Unevaluated |
| CHCP student portal | No | No | Fail |
| Mobilelink (public site) | Not documented | Not documented | Unevaluated |
| Earthbound account login | No | No | Fail |

Takeaway: CHCP’s student-portal guide and Earthbound’s customer login describe username/password access with no advertised YubiKey / FIDO or open Google Authenticator / Proton Pass TOTP — a Fail under this scorecard. Gulshan and Mobilelink lack useful public consumer MFA docs (Unevaluated). Workforce tenants may differ; affected Texans should still harden banks, email, and password managers with hardware keys or open TOTP while notices circulate.
Website stack note
Passive website-tech probes on August 4, 2026:
| Host | Notable signal |
|---|---|
| gulshanenterprises.com | WordPress 6.9.5 (wordpress.org latest 7.0.2); PHP 8.2.30 supported |
| chcp.edu | Platform undetected; valid Google Trust Services TLS |
| mobilelinkusa.com | Platform undetected; valid GlobalSign TLS |
| earthboundtrading.com | Magento fingerprint (version not exposed); Let’s Encrypt TLS |
Stack age does not prove lawsuit root cause. Gulshan’s outdated WordPress core is still a hygiene flag worth closing independently of the Qilin litigation narrative.
Email blacklist check
MX/domain DNSBL checks on August 4, 2026 (public DoH; some Spamhaus/URIBL rows unavailable — verify on check.spamhaus.org if deliverability is disputed):
| Domain | Mail/domain status | Note |
|---|---|---|
| gulshanenterprises.com | Listed | MX 172.65.182.103 on SPFBL |
| chcp.edu | Clear | CDN SPFBL notes only (not mail reputation) |
| mobilelinkusa.com | Clear | — |
| earthboundtrading.com | Clear | Fastly/CDN SPFBL notes only |
Lookalike / cybersquat scans
BEC-profile cybersquat scans on August 4, 2026. Prefer official notice URLs from the mailed letter — see Cybersquat Domain Monitoring.
| Brand domain | To review | Highest-risk hit |
|---|---|---|
| gulshanenterprises.com | 1 | gulshanenterprise.com (omission; NS/A/MX) |
| chcp.edu | 10 | chcp.com / .net / .org TLD swaps (short .edu omissions are often unrelated schools) |
| mobilelinkusa.com | 4 | mobillinkusa.com — BEC staging (NS + MX, no useful website A/AAAA) |
| earthboundtrading.com | 2 | earthboundtradin.com, earthboundtrading.co (.biz/.net redirect to brand) |

Priority actions
If you received a notice from any of these orgs:
- Enroll in credit monitoring only via the letter’s URL or phone number.
- Treat unexpected “portal reset,” refund, or ACH emails as suspicious until verified out-of-band.
- Freeze credit when SSNs were listed; enable carrier PIN / port-out protection if you shopped at a wireless retailer.
For operators in active Texas breach litigation:
- Close the shared 15% transport gap with MTA-STS enforce + TLS-RPT toward the 100% ideal.
- Publish consumer/student MFA that includes open TOTP and, where feasible, YubiKey / FIDO.
- Monitor registered lookalikes — especially BEC staging hosts with MX and no website.
Related coverage (deep dives)
- Gulshan Management Qilin breach litigation
- CHCP / Empowerment Schools breach litigation
- Mobilelink breach litigation
- Earthbound Holding breach litigation
- Texas OAG YTD dashboard
- National banks MFA / SIM-swap scoreboard
- All state AG trackers
Run a free Instant Cybersecurity Audit at audit.emailmenow.com or contact EmailMeNow IT Consulting for breach-notice email hardening and lookalike monitoring.
Sources: Texas OAG — Data Security Breach Reports · CourtListener — In Re Gulshan 4:26-cv-00200 · CourtListener — Johnson v. Empowerment / CHCP 4:26-cv-01747 · CourtListener — Dudsic v. Master MobileLink 4:26-cv-02565 · CourtListener — In re Earthbound Holding 3:26-cv-01096 · EmailMeNow audits