A cybersecurity incident at prominent US law firm Sheppard Mullin Richter & Hampton has triggered a proposed class action lawsuit, with a former employee alleging that the firm failed to adequately protect sensitive personal information, including Social Security numbers and driver’s license details.
The lawsuit was filed in federal court in California, shortly after the firm notified state authorities in California, Texas and other jurisdictions about the incident.
According to the firm’s disclosures, the breach occurred on August 31 and exposed personal information contained in certain documents. The incident has added to mounting concerns over cybersecurity vulnerabilities across the legal sector, where firms routinely handle confidential client records and sensitive individual data.
Sheppard Mullin, which employs approximately 1,200 attorneys, has maintained that the breach was limited in scope. In a statement, the firm said only a limited number of documents were involved and that its systems and network had not been accessed.
The firm also said it had contacted affected clients and individuals, reaffirming its commitment to safeguarding the information entrusted to it.
Lawsuit Alleges Failures in Cybersecurity Safeguards
The complaint accuses Sheppard Mullin of failing to provide adequate cybersecurity training to employees and maintain reasonable security measures to protect personal information.
The firm reportedly attributed the incident to a so-called social engineering attack involving one of its attorneys. Such attacks typically rely on deception or manipulation to persuade individuals to disclose confidential information or enable unauthorised access.
The plaintiff, whose relationship with the firm is identified as former employment, alleges negligence and violations of California’s unfair business practices law, among other claims.
She has asked the court to certify the case as a class action representing more than 1,000 individuals who may have been affected. The lawsuit seeks damages exceeding $5 million.
The allegations have not yet been established in court, and the firm had not entered an appearance in the case at the time of the report.
Cybersecurity Concerns Spread Across the Legal Industry
The lawsuit comes amid a series of reported cyber incidents involving major law firms. Recent disclosures by firms including Quinn Emanuel and Herbert Smith have highlighted the growing risks faced by legal practices handling vast amounts of confidential information.
Other firms have also encountered legal challenges following security incidents. WilmerHale faced a proposed class action in federal court in Washington in July over an alleged data breach, while Greenberg Traurig has faced similar litigation.
The latest case underscores the potential consequences of cybersecurity failures for law firms, where the exposure of personal information can lead not only to regulatory scrutiny but also to costly litigation and reputational damage.
The case is Pena-Emilia Williams v. Sheppard Mullin Richter & Hampton, filed in the US District Court for the Central District of California under case number 2:26-cv-11730.

