A former employee of Sheppard Mullin Richter & Hampton LLP filed a proposed class action lawsuit against the law firm on Wednesday, Oct. 7, 2026, following a data security breach that occurred in late August. The lawsuit, filed in the U.S. District Court for the Central District of California, alleges that the breach exposed Social Security numbers, driver’s license numbers, and other sensitive personal information.
The legal action followed disclosures by the Los Angeles-founded firm to state attorneys general in California, Texas, and other states. Sheppard Mullin reported that the incident occurred on Aug. 31, 2026, when an attorney at the firm was targeted in a social engineering event. The firm stated it became aware of the matter on Sept. 1, 2026, and hired an outside forensic firm and other third-party specialists to assist in an investigation.
Sheppard Mullin, which employs approximately 1,200 attorneys, stated this week that the breach involved a limited number of documents and that there was no unauthorized access to the firm’s broader systems or network. The firm began mailing notification letters to affected individuals on Oct. 2, 2026. According to the firm, it has already communicated with impacted clients and individuals and has found no evidence that the information has been used fraudulently.
The lawsuit, brought by plaintiff Pena-Emilia Williams, alleges that Sheppard Mullin failed to adequately train employees on cybersecurity and failed to maintain reasonable security protocols. The complaint asserts claims of negligence and violations of California’s unfair business practices law. Williams is seeking class action status for more than 1,000 individuals and damages exceeding $5 million.
For those whose information was exposed, the immediate impact involves a heightened risk of identity theft. Sheppard Mullin is offering affected individuals a 24-month membership in credit monitoring and identity protection services through TransUnion, which includes triple bureau monitoring and up to $1 million in identity theft insurance. However, individuals must enroll by the Dec. 31, 2026, deadline to receive these benefits. The legal industry has seen a rise in such incidents, with other firms like WilmerHale, Quinn Emanuel, and Herbert Smith also reporting recent breaches.
This case could establish how professional service firms are held accountable for social engineering attacks, where employees are manipulated into disclosing files. The outcome could influence security training standards and liability for law firms that handle large volumes of third-party personal data. The court must decide whether to grant class action status to the lawsuit. No legal representative for the defendant has made an appearance in the court case as of Oct. 8, 2026.
