Back to news
Cybersecurity Alert
August 4, 2026 by EmailMeNow IT Consulting

Texas Breach Lawsuit Defendants Scoreboard — None Hit 100% Domain Security

CourtListener Batch A Texas data-breach defendants ranked by domain audit (ideal 100%): Mobilelink 84%, Earthbound 73%, CHCP 60%, Gulshan 43%. All show 15% transport; lookalikes and MFA gaps called out.

Source: Texas OAG · CourtListener

NewsData BreachClass ActionTexasMFAYubiKeyAuthenticator AppsCybersecurity
Texas federal breach-litigation defendants ranked on a domain security scoreboard below 100% ideal

Four Texas organizations with confirmed AG notices and active federal data-breach class actions sit on the same scoreboard this week: Gulshan Management Services, the College of Health Care Professions (Empowerment Schools), Mobilelink, and Earthbound Holding. Dedicated deep-dives already cover each case — this post is the comparative audit / MFA / lookalike rollup, not a rehash of any single lawsuit.

We re-confirmed the lead dockets on CourtListener, ran fresh EmailMeNow domain audits (100% is the ideal), probed website stacks, checked mail/domain blacklists, scanned cybersquat lookalikes, and reviewed public docs for YubiKey / FIDO and open Google Authenticator–style TOTP.

Texas federal breach-litigation defendants ranked on a domain security scoreboard below 100% ideal

Defendants at a glance

Texan impact figures are from Texas OAG breach reports. Docket links point at the lead / In Re case — not every member filing.

OrganizationTexansLead docket (filed)Domain
Gulshan Management Services128,652S.D. Tex In Re 4:26-cv-00200 (Jan 12, 2026)gulshanenterprises.com
CHCP / Empowerment Schools68,927S.D. Tex 4:26-cv-01747 (Mar 3, 2026)chcp.edu
Mobilelink (Master MobileLink)12,201S.D. Tex lead 4:26-cv-02565 (Mar 31, 2026)mobilelinkusa.com
Earthbound Holding1,866N.D. Tex In Re 3:26-cv-01096 (Apr 6, 2026)earthboundtrading.com

Combined Texas residents in notices: ~211,646. Sector mix: convenience retail (Qilin), healthcare education, wireless retail, specialty retail.

Independent cybersecurity audits

EmailMeNow audits on August 4, 2026. 100% is the ideal overall score — 0 of 4 reached it. Scores measure public identity / transport / website posture, not whether a jury has ruled on the underlying breach claims.

OrganizationDomainOverallIdentityTransportWebsite
Mobilelinkmobilelinkusa.com84%90%15%92%
Earthbound Holdingearthboundtrading.com73%65%15%87%
CHCP / Empowermentchcp.edu60%70%15%37%
Gulshan Managementgulshanenterprises.com43%10%15%62%

Domain audit dashboard with Transport at 15% across four Texas lawsuit defendants

Patterns:

  • Transport = 15% on all four — none show effective MTA-STS mode=enforce. Spoofed “breach notice / credit monitoring” mail stays easy to deliver during litigation headlines.
  • Strongest overall: Mobilelink 84% (still short of 100%). Weakest: Gulshan 43% with 10% identity — high spoofing risk for Handi Stop / Gulshan-branded mail.
  • CHCP leads identity among the lower half (70%) but lags website hardening (37%).

Audit links: mobilelinkusa.com · earthboundtrading.com · chcp.edu · gulshanenterprises.com

MFA: YubiKey & Google Authenticator

Public consumer / student documentation only. Grade: Fail = SMS/voice/email OTP or password-only with no stronger factor documented; Partial = proprietary soft token / push without open TOTP or YubiKey; Pass = open TOTP; Strong = FIDO/YubiKey; Unevaluated = no useful public MFA docs.

OrganizationYubiKey / FIDOOpen TOTPGrade
Gulshan (consumer)Not documentedNot documentedUnevaluated
CHCP student portalNoNoFail
Mobilelink (public site)Not documentedNot documentedUnevaluated
Earthbound account loginNoNoFail

MFA grading tray: SMS Fail, authenticator Pass, YubiKey Strong — CHCP and Earthbound Fail

Takeaway: CHCP’s student-portal guide and Earthbound’s customer login describe username/password access with no advertised YubiKey / FIDO or open Google Authenticator / Proton Pass TOTP — a Fail under this scorecard. Gulshan and Mobilelink lack useful public consumer MFA docs (Unevaluated). Workforce tenants may differ; affected Texans should still harden banks, email, and password managers with hardware keys or open TOTP while notices circulate.

Website stack note

Passive website-tech probes on August 4, 2026:

HostNotable signal
gulshanenterprises.comWordPress 6.9.5 (wordpress.org latest 7.0.2); PHP 8.2.30 supported
chcp.eduPlatform undetected; valid Google Trust Services TLS
mobilelinkusa.comPlatform undetected; valid GlobalSign TLS
earthboundtrading.comMagento fingerprint (version not exposed); Let’s Encrypt TLS

Stack age does not prove lawsuit root cause. Gulshan’s outdated WordPress core is still a hygiene flag worth closing independently of the Qilin litigation narrative.

Email blacklist check

MX/domain DNSBL checks on August 4, 2026 (public DoH; some Spamhaus/URIBL rows unavailable — verify on check.spamhaus.org if deliverability is disputed):

DomainMail/domain statusNote
gulshanenterprises.comListedMX 172.65.182.103 on SPFBL
chcp.eduClearCDN SPFBL notes only (not mail reputation)
mobilelinkusa.comClear
earthboundtrading.comClearFastly/CDN SPFBL notes only

Lookalike / cybersquat scans

BEC-profile cybersquat scans on August 4, 2026. Prefer official notice URLs from the mailed letter — see Cybersquat Domain Monitoring.

Brand domainTo reviewHighest-risk hit
gulshanenterprises.com1gulshanenterprise.com (omission; NS/A/MX)
chcp.edu10chcp.com / .net / .org TLD swaps (short .edu omissions are often unrelated schools)
mobilelinkusa.com4mobillinkusa.comBEC staging (NS + MX, no useful website A/AAAA)
earthboundtrading.com2earthboundtradin.com, earthboundtrading.co (.biz/.net redirect to brand)

Spoofed breach-notice email beside registered lookalike and BEC-staging domain cards

Priority actions

If you received a notice from any of these orgs:

  • Enroll in credit monitoring only via the letter’s URL or phone number.
  • Treat unexpected “portal reset,” refund, or ACH emails as suspicious until verified out-of-band.
  • Freeze credit when SSNs were listed; enable carrier PIN / port-out protection if you shopped at a wireless retailer.

For operators in active Texas breach litigation:

  • Close the shared 15% transport gap with MTA-STS enforce + TLS-RPT toward the 100% ideal.
  • Publish consumer/student MFA that includes open TOTP and, where feasible, YubiKey / FIDO.
  • Monitor registered lookalikes — especially BEC staging hosts with MX and no website.

Run a free Instant Cybersecurity Audit at audit.emailmenow.com or contact EmailMeNow IT Consulting for breach-notice email hardening and lookalike monitoring.


Sources: Texas OAG — Data Security Breach Reports · CourtListener — In Re Gulshan 4:26-cv-00200 · CourtListener — Johnson v. Empowerment / CHCP 4:26-cv-01747 · CourtListener — Dudsic v. Master MobileLink 4:26-cv-02565 · CourtListener — In re Earthbound Holding 3:26-cv-01096 · EmailMeNow audits