Data Breach · Lawsuit Filed

Nelson Mullins Data Breach Class Action Filed Over Unconfirmed Ransomware Claim

Published October 9, 2026

People whose personal information was held by the law firm Nelson Mullins may be covered by a proposed class action alleging Nelson, Mullins, Riley & Scarborough LLP failed to protect that data in a reported October 2026 cyberattack that the firm has not publicly confirmed. No class has been certified and there is nothing to file yet.

Nelson Mullins data breach class action lawsuit over an alleged October 2026 ransomware attack on the law firm
▼ Allegations Only · No Settlement Yet

This article describes a class action complaint. The statements below are unproven allegations. Nelson, Mullins, Riley & Scarborough LLP has not been found liable, there is no certified class, and nothing to claim at this time. The firm had not publicly confirmed any data breach when the complaint was filed. This page is informational and is not legal advice.

What Is This About?

Nelson Mullins, a national law firm headquartered in Columbia, South Carolina, was sued in a proposed class action on October 7, 2026, two days after a ransomware tracking site reported that an extortion group had listed the firm as a victim. The case is Johnson v. Nelson, Mullins, Riley & Scarborough LLP, No. 3:26-cv-04508-MGL, in the U.S. District Court for the District of South Carolina, Columbia Division.

The complaint alleges the firm did not use reasonable security to protect personal information it held and that this information was potentially compromised. It is an unusually early filing: the complaint states outright that Nelson Mullins had not publicly confirmed any breach when the suit was filed, and it does not identify what kind of data was involved or how many people may be affected. None of the allegations has been proven.

Status Complaint Filed filed October 7, 2026 · District of South Carolina
Breach Confirmed? Not by the firm based on a ransomware group’s October 5, 2026 listing · no notice letters made public
People Affected Not disclosed the complaint estimates thousands, if not more
Can I Claim? No — nothing to claim yet no certified class · no settlement · no claim form

What Has Been Reported About the Incident?

The lawsuit’s account of the incident comes from a single source: Ransomware.live, a site that logs claims posted on extortion groups’ leak sites. According to the complaint, Ransomware.live reported on or about October 5, 2026 that a group known as SilentRansomGroup had listed Nelson Mullins in connection with an alleged cyberattack, and gave the same date as the approximate date of the attack. The complaint also cites the listing for an $8 million figure tied to keeping the allegedly obtained data from being published.

A leak-site listing is a claim made by the group itself. As of October 9, 2026, Nelson Mullins had not publicly confirmed an incident, no breach notice letters had been made public, and no filing with a state attorney general’s breach portal had surfaced. Independent breach trackers describe the listing as unverified, note that it did not include data samples or file counts, and do not agree on which group posted it. Coverage of the listing says the same group named another large U.S. law firm on the same day; that firm is not part of this case.

What Does the Complaint Allege?

The plaintiff, a resident of Charlotte, North Carolina, alleges that his personal information came into the firm’s possession through his relationship with it and was kept as part of its ordinary business. The complaint does not describe that relationship further. It alleges he has spent hours reviewing accounts and monitoring his credit since the reported attack and has seen an increase in spam calls, messages and emails.

The complaint asserts five claims: The plaintiff asks the court to certify a class, declare that the firm’s conduct violated the laws cited, and award damages, any available statutory damages, restitution, pre-judgment interest, and attorneys’ fees and costs. He demands a jury trial. Nelson Mullins had not filed a response as of October 9, 2026.

Who Does the Proposed Class Cover?

The complaint proposes a single nationwide class:

“All persons in the United States whose Private Information was potentially compromised in the alleged Data Breach (the ‘Class’).”

The firm, its officers, directors and affiliates, and the judge assigned to the case and the judge’s immediate family are excluded. Because the firm has not said whether any data was taken, or whose, the definition does not yet identify a concrete group. A law firm can hold personal information belonging to its clients, people on the other side of its clients’ matters, and its own personnel; the complaint does not say which of these groups, if any, is involved. The plaintiff reserves the right to amend the definition as the case develops.

What Happens Next?

The next step is for Nelson Mullins to respond to the complaint. In data breach cases filed before any official notice, defendants commonly challenge whether plaintiffs have standing — that is, whether they can show their own data was taken and that they suffered a concrete injury. The firm may also issue notice letters or regulatory filings if its own investigation finds that personal information was accessed, which would fill in the dates, data types and number of people that the complaint leaves open.

Additional lawsuits are common after a law-firm breach becomes public, and related cases in the same court are often consolidated. No class has been certified, and any recovery would come only through a settlement or a judgment, neither of which exists.

Law Firms and Data Breach Litigation

Law firms hold large amounts of sensitive client material, and several have faced breach suits in 2026. OpenClassActions.com has covered the WilmerHale data breach class action and the Blank Rome data breach class action, both filed after the firms sent notices. An earlier law-firm case has reached the settlement stage: the Pillsbury law firm data breach settlement covers people notified of an April 2025 breach. Unlike those cases, the Nelson Mullins suit was filed before the firm confirmed anything.

Questions

Has Nelson Mullins confirmed a data breach?

Not as of October 9, 2026. The complaint itself states that the firm had not publicly confirmed the alleged breach when the case was filed on October 7, 2026. The lawsuit relies on a report by the tracking site Ransomware.live that a group called SilentRansomGroup listed the firm on October 5, 2026. A listing by an extortion group is a claim by that group, not proof that data was taken.

What information was allegedly exposed in the Nelson Mullins incident?

The complaint does not identify specific data types. It says only that the alleged breach potentially compromised sensitive personal information the firm maintained. No breach notice letter or state attorney general filing describing the data had been made public as of October 9, 2026.

How many people were affected by the alleged Nelson Mullins breach?

No number has been disclosed. The complaint estimates the proposed class includes thousands of people, if not more, but that is the plaintiff’s estimate rather than a count from the firm or a regulator. No state attorney general breach listing for Nelson Mullins had surfaced as of October 9, 2026.

Who filed the Nelson Mullins data breach lawsuit?

A North Carolina resident filed the case, Johnson v. Nelson, Mullins, Riley & Scarborough LLP, No. 3:26-cv-04508-MGL, in the U.S. District Court for the District of South Carolina on October 7, 2026. The plaintiff is represented by Poulin | Willey | Anastopoulo, LLC and Levi & Korsinsky, LLP.

Is there a Nelson Mullins settlement or claim form?

No. The case is at the complaint stage. There is no certified class, no settlement and no claim form, and Nelson Mullins has not been found liable for anything. If the case is ever resolved through a settlement, a court-approved notice would explain who qualifies and how any claim process works.

Sources

• Johnson v. Nelson, Mullins, Riley & Scarborough LLP, No. 3:26-cv-04508-MGL (D.S.C.) — docket and complaint, filed October 7, 2026
• Ransomware.live — leak-site listing for Nelson Mullins Riley & Scarborough (cited in the complaint)
• Breachsense — breach tracker entry noting the claim is unconfirmed

For more class actions keep scrolling below.
Status Complaint filed — no settlement, no certified class
Case Title Johnson v. Nelson, Mullins, Riley & Scarborough LLP
Case Number 3:26-cv-04508-MGL
Court U.S. District Court, District of South Carolina (Columbia Division)
Date Filed October 7, 2026
Claims Negligence · negligence per se · unjust enrichment · breach of implied contract · breach of confidence
Court Docket CourtListener Docket

More Law Firm and Data Breach Cases