The Plain Record

Neutral daily news — clear headlines, complete facts.

Legal

Sheppard Mullin Faces Proposed Class Action After Data Breach Disclosures

A former employee has filed a proposed class action seeking over $5 million in damages after a social engineering event exposed sensitive data at the law firm.

Published October 8, 2026 at 11:01 AM EDT

The short answer

A former employee has filed a proposed class action seeking over $5 million in damages after a social engineering event exposed sensitive data at the law firm.

Sheppard Mullin Faces Proposed Class Action After Data Breach Disclosures

The Facts

Who
Pena-Emilia Williams (Plaintiff); Sheppard Mullin Richter & Hampton LLP (Defendant)
What
A proposed class action lawsuit was filed against law firm Sheppard Mullin following a data breach that exposed personal information, including Social Security numbers.
When
Wednesday, Oct. 7, 2026
Where
U.S. District Court for the Central District of California
Why
The breach exposed sensitive personal data of more than 1,000 people, leading to allegations of negligence and inadequate cybersecurity training.

A former employee of Sheppard Mullin Richter & Hampton LLP filed a proposed class action lawsuit against the law firm on Wednesday, Oct. 7, 2026, following a data security breach that occurred in late August. The lawsuit, filed in the U.S. District Court for the Central District of California, alleges that the breach exposed Social Security numbers, driver’s license numbers, and other sensitive personal information.

The legal action followed disclosures by the Los Angeles-founded firm to state attorneys general in California, Texas, and other states. Sheppard Mullin reported that the incident occurred on Aug. 31, 2026, when an attorney at the firm was targeted in a social engineering event. The firm stated it became aware of the matter on Sept. 1, 2026, and hired an outside forensic firm and other third-party specialists to assist in an investigation.

Sheppard Mullin, which employs approximately 1,200 attorneys, stated this week that the breach involved a limited number of documents and that there was no unauthorized access to the firm’s broader systems or network. The firm began mailing notification letters to affected individuals on Oct. 2, 2026. According to the firm, it has already communicated with impacted clients and individuals and has found no evidence that the information has been used fraudulently.

The lawsuit, brought by plaintiff Pena-Emilia Williams, alleges that Sheppard Mullin failed to adequately train employees on cybersecurity and failed to maintain reasonable security protocols. The complaint asserts claims of negligence and violations of California’s unfair business practices law. Williams is seeking class action status for more than 1,000 individuals and damages exceeding $5 million.

For those whose information was exposed, the immediate impact involves a heightened risk of identity theft. Sheppard Mullin is offering affected individuals a 24-month membership in credit monitoring and identity protection services through TransUnion, which includes triple bureau monitoring and up to $1 million in identity theft insurance. However, individuals must enroll by the Dec. 31, 2026, deadline to receive these benefits. The legal industry has seen a rise in such incidents, with other firms like WilmerHale, Quinn Emanuel, and Herbert Smith also reporting recent breaches.

This case could establish how professional service firms are held accountable for social engineering attacks, where employees are manipulated into disclosing files. The outcome could influence security training standards and liability for law firms that handle large volumes of third-party personal data. The court must decide whether to grant class action status to the lawsuit. No legal representative for the defendant has made an appearance in the court case as of Oct. 8, 2026.

Timeline of what happened

Key dates and decisions, in the order they occurred.

  1. August 31, 2026

    Data breach occurs via social engineering event

  2. September 1, 2026

    Sheppard Mullin identifies the security incident

  3. October 2, 2026

    Firm begins mailing notification letters to affected individuals

  4. October 7, 2026

    Lawsuit filed in U.S. District Court for the Central District of California

  5. December 31, 2026

    Deadline for affected individuals to enroll in credit monitoring services

Summaries are written by The Plain Record to state the facts of a story plainly and without political slant. Drafted with AI assistance and checked against the source record before publication. See how we report, or report a correction.

← Back to the front page

Questions readers ask

What happened: Sheppard Mullin Faces Proposed Class Action After Data Breach Disclosures?

A proposed class action lawsuit was filed against law firm Sheppard Mullin following a data breach that exposed personal information, including Social Security numbers.

Who is involved?

Pena-Emilia Williams (Plaintiff); Sheppard Mullin Richter & Hampton LLP (Defendant)

When did this happen?

Wednesday, Oct. 7, 2026

Where did this happen?

U.S. District Court for the Central District of California

Why does this matter?

The breach exposed sensitive personal data of more than 1,000 people, leading to allegations of negligence and inadequate cybersecurity training.