International law firm Sheppard Mullin is facing a proposed class-action lawsuit in the United States after disclosing a data breach involving sensitive personal information.
The firm, which has about 1,200 lawyers, said the security incident occurred on August 31 and involved a social-engineering attack directed at one of its attorneys.
Sensitive information allegedly exposed included Social Security numbers and driver’s licence information. Reuters
A former employee has now filed suit in federal court in California, accusing the firm of negligence and violations of California unfair-business-practices law.
The proposed class action seeks more than $5 million in damages on behalf of over 1,000 individuals.
Sheppard Mullin says the incident involved only a limited number of documents and that its wider computer systems were not compromised.
The lawsuit, however, alleges inadequate staff training and insufficient safeguards.
Those allegations remain unproven.
The dispute is important to the wider profession because law firms hold unusually sensitive information: litigation strategies, privileged communications, corporate transactions, personal records and confidential financial material.
That makes lawyers increasingly attractive targets for cybercriminals.
The case also raises a professional-responsibility question relevant far beyond the United States: when confidential information is lost through a cyberattack, where does technological failure end and professional negligence begin?
Related Stories
READ MORE: Technology Adoption in Nigerian Law Firms and Its Legal Ethical Implications Nigerian Law Updates
READ MORE: Judges Warn Against AI Overreliance in Courts Nigerian Law Updates
behind Games Village, Abuja
5A, CGH, Games Village, Abuja
