Sheppard Mullin Breach: Why Document Requests Need Verification
Sheppard Mullin says one attorney was deceived into disclosing documents. Learn how small law firms can verify requests and reduce the risk of data theft.
Blog post - By Securing Your Law Firm
Explore cybersecurity awareness training for law firms | Get your free Zero-Access Exposure Review™
A firm does not need to lose access to its network for client documents to be exposed.
Sheppard, Mullin, Richter & Hampton LLP says one attorney was deceived into disclosing documents. In its October 2 notice filed with California's Attorney General, the firm says there was no unauthorized access to or compromise of its systems or network.
For a small firm, this is a familiar operational risk: an employee with legitimate access can be persuaded to send files to the wrong person. The safeguards have to cover those decisions, not only network access.
What is confirmed about the Sheppard Mullin incident?
The firm's sample notification letter sets out a short timeline:
- August 31, 2026: A social engineering incident involving one attorney resulted in documents being disclosed to an unknown third party.
- September 1: The firm became aware of the incident, began investigating, engaged outside forensic and other experts, and notified law enforcement.
- October 2: The sample notice was dated and the incident appeared in California's breach reporting records.
The letter says impacted files contained personal information and offers affected recipients 24 months of credit monitoring and identity protection. The public sample redacts the specific fields, so it does not show exactly what information was exposed for each person.
On October 8, Reuters reported that a former employee had filed a proposed class action. The complaint, filed October 7, alleges inadequate safeguards and training. The allegations have not been decided by a court.
What is known about the Silent Ransom Group claim?
DeXpose reported on October 6 that Silent Ransom Group had listed the firm as a victim the day before.
The firm's notice does not identify an attacker or explain how the deception happened. A listing on a leak site does not confirm who was responsible, what information the group holds, or whether a payment was made. It also does not show that a fake support call, remote session, or in-person visit was involved here.
Why fake IT support deserves your firm's attention
In a May 26, 2026 advisory, the FBI warned that Silent Ransom Group targets law firms through IT impersonation, phone calls, and phishing emails. It described both remote-access schemes and individuals posing as technicians to gain physical access to computers.
The FBI describes a group that steals data and threatens to disclose it rather than relying on traditional file-encrypting ransomware. We explain the broader playbook in our article on Silent Ransom Group's law firm extortion tactics.
Mandiant's June 5 research adds a useful detail: some opening emails contained no active links or malicious attachments. They helped establish a pretext for a follow-up call. In investigated cases, attackers sometimes persuaded employees to gather and send documents themselves.
An October 8 investigation by Recorded Future News examined leaked conversations about planned office infiltration. The outlet cautioned that the archive included a mix of apparent activity, boasting, and unverified plans. None of this establishes how the Sheppard incident happened.
The request itself deserves as much scrutiny as the email or call that delivers it. A request to upload matter files, share screen control, or help "back up" documents should be verified, even if there is no suspicious link or attachment.
Why this matters even if your firm has MFA and backups
Multi-factor authentication helps protect accounts, and backups help restore files. Neither can tell an employee whether a document request is legitimate.
An employee might be asked to upload files to a supposed migration folder or email records to someone claiming to be support. That is one plausible example, not a description of what happened at Sheppard Mullin.
At a small firm, one person may have legitimate access to several matters, client identification records, financial documents, or staff records. A convincing request can put all of that within reach without disrupting email or document systems.
Five steps your firm can take this week
1. Give everyone a trusted way to verify support requests
Post the approved IT support number and request process where staff can find them quickly. If an unexpected caller asks for access, an installation, or documents, staff should pause and contact the provider through that saved number or the firm's usual ticket process.
Never use a number or link supplied by the caller to verify the request. A familiar name, caller ID, or knowledge of the firm is not independent confirmation. Agree on the procedure with your IT provider and share it with attorneys, staff, and reception.
2. Require a second check for unusual document transfers
Ask the responsible attorney or designated administrator to approve unusual bulk exports, uploads to new destinations, or transfers outside the normal matter workflow.
Before sending, confirm who requested the files, why they are needed, and where they will go. Use the firm's approved sharing process and check that the intended recipient has the right access.
Ask your administrator who can review external shares and bulk downloads. If you want a demonstration, use harmless test files, not client records.
3. Check which remote-support tools are allowed
Ask your IT provider for a list of approved support tools and how staff should authorize a session. Have the provider check for unapproved tools and explain whether they can block them or limit unexpected screen-control requests.
Keep a dated copy of the inventory, approved list, and any restrictions or exceptions. Finding legitimate support software on a computer does not prove an attack; who authorized it and how it was used are what matter.
Our article on how fake IT support can misuse ScreenConnect explains how familiar tools can be turned into an access route.
4. Verify technicians before they reach a computer
Reception should check a technician's visit against a scheduled appointment and confirm it with the provider using a known number. An ID badge or plausible explanation is not enough to authorize access to a computer.
Escort visitors. Require approval before they connect storage devices or copy files, and ask your administrator whether USB storage restrictions make sense for computers holding sensitive information. Make sure reception follows the same verification process as everyone else.
5. Practice the decision and make reporting easy
Run a short discussion exercise: an unexpected caller reports a security problem and asks an attorney to upload a matter folder. Who verifies the caller? Who approves the transfer? Who should be contacted if the files have already been sent?
Include partners, attorneys, assistants, and reception. Staff should know that they are expected to report a mistake right away, without waiting to see what happens. Record when you ran the exercise, who took part, and which gaps need an owner.
If someone has already shared files or granted access
Stop the interaction and contact the firm's response lead and trusted IT contact immediately through a known channel. If remote control is active, have the device isolated from the network; avoid wiping or resetting it before responders can preserve evidence.
Keep the original messages, sender addresses, phone numbers, destinations, times, and a record of what was shared. A changed password does not retrieve disclosed documents.
The response lead should coordinate technical review, counsel, and any insurer reporting required by the policy. Prepare in advance with our law firm incident response plan template, which helps name contacts and responsibilities before an incident.
Build verification into everyday legal work
The disclosure is a useful prompt for firm leaders: review how staff approve access and handle unusual document requests. The rule should be easy to remember—pause, verify through a known channel, and report concerns promptly.
Staff are more likely to follow that rule if they have practiced it. Cybersecurity Awareness Training for Law Firms gives attorneys and staff weekly, law-firm-specific email challenges with practical decision feedback. Administrators can track completion and scores. Use that practice alongside written procedures and technical safeguards.
If your firm also wants to understand what attackers can learn from its public-facing information, the Free Zero-Access Exposure Review™ checks public DNS and web records only. It does not inspect computers or determine whether someone has accessed firm systems.
Related reading
- How Threat Actors Use ScreenConnect Against Law Firms
- When BigLaw Pays $46 Million, Your Five-Attorney Firm Is the Easier Target
- Law Firm Incident Response Plan Template
- Cybersecurity Awareness Training for Law Firms
Reporting reviewed through October 8, 2026. The firm's account, litigation allegations, and threat-actor claims are distinguished above; the exact deception and attacker attribution remain unconfirmed in the cited firm notice. This article is informational and does not constitute legal advice.
