2026 Sheppard Mullin — attorney social engineering; document disclosure (CA AG notice)
Data compromised
Personal information in impacted legal-service documents (varies). CA AG filing summaries list categories that may include name, SSN, DOB, wage/compensation, tax-return info, direct-deposit details, home address, telephone. Nationwide census unpublished (recordsAffected 0).
Technical writeup
Verified firm notice filed with California AG (sample individual letter; notices mailed ~Oct 2, 2026) — On August 31, 2026 a single Sheppard, Mullin, Richter & Hampton LLP attorney was victim of a sophisticated social-engineering event resulting in unauthorized disclosure of certain documents to an unknown third party. Firm states the incident was limited to that individual with no unauthorized access to or compromise of firm systems/network. Aware Sep 1; engaged forensics and law enforcement; offering 24 months Cyberscout monitoring. Headcount unpublished. Multiple plaintiff firms publicly investigating potential class actions as of early October; treat lawsuit status as investigations unless a filed complaint is cited.
Root cause
Sophisticated social engineering of a single attorney on Aug 31 2026 led to unauthorized disclosure of certain documents; firm states no network/system compromise