BlackTree Security · Infrastructure · Automation · AI

Sheppard Mullin Attorney Disclosure Affected 2,326 Texans

A single Sheppard Mullin attorney was socially engineered into disclosing documents to an unknown third party on 31 August 2026. The firm says its systems and network were not accessed or compromised. The Texas register lists 2,326 residents as affected.

This was document disclosure, not a network intrusion

Sheppard says it discovered the incident on 1 September. The individual notice is dated 2 October. Texas published its row on 6 October.

Texas lists sensitive identity categories

The Texas row lists Social Security number information, driving licence number, government-issued identification and an Other category. The public sample redacts the recipient’s specific field. Do not assume that every Texas category applied to every person.

The notice says approximately 29 Rhode Island residents may be affected. That figure is separate from Texas and is not a national total.

Sheppard says it found no evidence of fraudulent use at notice time. This does not guarantee that later misuse will be prevented or immediately detected.

Match the response to your own notice

The notice offers 24 months of monitoring and identity protection, with enrolment required by 31 December 2026. Verify the letter through an official Sheppard channel before entering a code or personal information on a website.

If your notice identifies a Social Security number, driving licence or another government identifier, consider freezing your credit with each major bureau. Review credit and account activity, retain the letter and report transactions or accounts you do not recognise.

Be alert for follow-up messages that use legal context or personal details to appear credible. BlackTree’s analysis of two other law-firm incidents explains why document exposure can matter even when only one user or account is involved. That comparison does not imply a shared attacker, technique or organisation.

Sources: the California attorney general’s SB24-630779 filing and sample individual notice; and the Texas attorney general’s Data Security Breach Reports register.

Leave a Reply

Your email address will not be published. Required fields are marked *