Data breach
Mobilelink USA
- Records
- 2,689,235
- Breach date
- 2 December 2025Estimated
- Added
- 27 April 2026
What was exposed
10 types of data · 1 more reported · 3 put you at serious risk
- Phone numbers2,689,235
- Names799,253
- Email addresses204,238
- Dates of birth72,547
- Street addresses61,625
- Social security numbers47,643
- Licence plates53
- Vehicle VINs48
- Bank account numbers24
- Passport numbers1
- Government IDsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Mobilelink USA, a Texas-based wireless retailer and one of the largest authorized sellers of Cricket Wireless products in the United States, was hit by a cyberattack in December 2025 that exposed personal information belonging to tens of thousands of people, and according to regulatory filings, far more records may have been swept up in the incident. The DragonForce ransomware group claimed responsibility on a dark web leak site on December 2, 2025, stating it had stolen 5.04 terabytes of data from the company, which operates as Master Mobilelink LLC and Mobily LLC from its base in Sugar Land, Texas. The company began mailing notification letters to affected individuals in late March 2026, roughly four months after the group's public claim. Our investigation team estimates the breach involved 2,689,235 rows of data, while filings with multiple state attorneys general put the number of notified individuals at 40,174.
Breach Timeline
December 2, 2025: The DragonForce ransomware group posted a claim on its dark web leak site saying it had obtained 5.04 terabytes of data from Mobilelink and threatened to publish it within seven to eight days, as tracked by ransomware.live and reported by BlackFog.
February 26, 2026: Mobilelink discovered the breach, according to ClaimDepot's summary of the company's regulatory filings.
March 27, 2026: The company notified consumers and filed breach reports with state attorneys general, including those of Texas, Indiana, Massachusetts, New Hampshire, Nebraska, and Vermont.
What Information Was Compromised?
Our analysis found the following data types in this breach: names, Social Security numbers, dates of birth, email addresses, phone numbers, street addresses, vehicle identification numbers, vehicle license plates, and bank account information. According to our investigation team, phone numbers appeared in the largest volume, with more than 2.68 million records containing one, while 47,643 records included Social Security numbers and 72,547 included dates of birth.
The company's notice letter, filed with state regulators, additionally lists government-issued identification cards, Social Security cards, and financial information such as account numbers among the exposed data types.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Social Security numbers paired with names and dates of birth are the raw material for identity theft. Someone holding that combination can attempt to open credit accounts, file fraudulent tax returns, or impersonate victims with government agencies. Financial account details in the breach raise the risk of direct account fraud. Phone numbers and email addresses are useful for phishing, and scammers often pose as the breached company itself to extract more information from people who know they were affected. Because DragonForce threatened to publish the stolen data, affected individuals should assume their information could circulate among criminal groups for years.
What Is Mobilelink USA Doing in Response?
Mobilelink is notifying affected individuals by letters sent through U.S. Mail, according to its filings with state attorneys general. The company disclosed the breach to regulators in more than a dozen states, including Texas, Indiana, Massachusetts, New Hampshire, Nebraska, Vermont, California, Maine, and Washington, as well as to the U.S. Department of Health and Human Services. As of September 25, 2026, we have not found detailed public statements from the company describing the technical cause of the breach or any remediation measures.
What Should You Do If You Were Affected?
If you receive a notification letter from Mobilelink, read it carefully and follow any instructions it contains, including any offer of credit monitoring. Place a credit freeze or fraud alert with Equifax, Experian, and TransUnion to block unauthorized new accounts. Review your credit reports at AnnualCreditReport.com and your bank and credit card statements for unfamiliar activity. Consider requesting an Identity Protection PIN from the IRS, since Social Security numbers and dates of birth were involved. Report suspected identity theft at IdentityTheft.gov. Finally, treat unexpected calls, texts, or emails about this breach with suspicion; legitimate notifications arrived by mail.
