
A social engineering attack on an employee at Troutman Pepper Locke, one of Atlanta's largest and oldest law firms, has triggered a proposed class action lawsuit alleging that private information belonging to roughly 37,000 people was exposed. The breach, which occurred on August 7, has landed the firm in the position of defending itself against the very type of litigation its own attorneys are often hired to fight off.
According to the lawsuit, filed in federal court in Atlanta by a West Virginia resident, the plaintiff is one of around 37,000 people now at risk of fraud and identity theft because of the exposure. As reported by The Atlanta Journal-Constitution, an employee at the firm interacted with communications that appeared legitimate but were not, a description that matches a wave of impersonation scams the FBI has tied to law firms nationally.
Troutman Pepper Locke has confirmed it engaged a cybersecurity specialist and notified the FBI after discovering the intrusion, per the firm's own statement cited in the AJC's report. The firm maintains a locally headquartered office in Atlanta and is described in the same reporting as one of the city's largest and oldest legal practices, with roots the firm traces back to 1897.
A Firm Built From a Massive 2025 Merger
Troutman Pepper Locke was formed on January 1, 2025, when Atlanta-based Troutman Pepper Hamilton Sanders merged with Dallas-based Locke Lord, creating a firm with more than 1,600 attorneys spread across more than 30 offices, according to background reporting from AJC.com. The combined firm brought in roughly $1.5 billion in revenue, placing it among the top 30 U.S. legal firms by that measure. Its flagship Atlanta office sits at Bank of America Plaza on Peachtree Street, home to about 200 attorneys and 300 support staff.
The firm's own Privacy, Cyber, and Data Security practice group regularly defends corporate clients against exactly this kind of data breach class action and against state attorney general investigations, according to the firm's own description of its practice. That makes the current lawsuit a notable reversal: the same institutional expertise the firm sells to clients apparently did not stop an employee from being fooled by a fraudulent contact.
Federal Warnings About Law Firms as Targets
The breach lands amid a documented surge in cyberattacks aimed squarely at law firms. The FBI issued a public alert in May warning that a threat group tracked as Silent Ransom Group, also known as Luna Moth, Chatty Spider, or UNC3753, has been actively targeting U.S. law firms using voice phishing and IT support impersonation to steal data without deploying traditional file-encrypting ransomware. It is not established whether that specific group was behind the Troutman Pepper Locke incident, and that link remains an open question.
A June 2026 Mandiant threat research report, detailed on the Google Cloud blog, found that these social engineering campaigns have escalated to include attackers physically visiting law offices while posing as IT personnel, sometimes exfiltrating data directly from endpoints using USB drives. A March 2026 report by Baker & Hostetler, covered by the ABA Journal, found that cyber incidents targeting law firms nearly doubled in 2025 compared to the prior year, as attackers increasingly go after legal entities holding troves of confidential client files.
Ethics Rules and Legal Exposure
Under the Georgia Personal Identity Protection Act, any entity that maintains computerized personal data must notify affected residents without unreasonable delay once it discovers a security breach. Separately, American Bar Association Model Rules 1.1 and 1.6 impose an affirmative duty on attorneys to maintain technological competence and take reasonable steps to prevent unauthorized disclosure of client information, obligations enforced through state bar disciplinary proceedings. Whether state bar authorities will scrutinize the firm's cybersecurity controls under those rules remains unresolved.
Precisely what categories of client or employee data were exfiltrated has not been detailed in the litigation as reported. The breach also arrives as Troutman Pepper Locke navigates other legal disputes: in August, a firm associate filed a federal lawsuit in New Jersey alleging he faced adverse employment actions after taking medical leave for a heart attack and after raising concerns about partner billing practices. That followed an April settlement of a $35 million race-bias suit the firm reached with a former associate shortly before it was set to go to trial.
The breach also fits a broader pattern of Atlanta-area organizations grappling with social engineering and credential-based attacks this year, echoing an incident in which Chick-fil-A One accounts were compromised through credential stuffing. For the roughly 37,000 people named in the proposed class action, the immediate concern is narrower: whether the exposure of their private information leaves them exposed to fraud and identity theft, and how the firm ultimately responds in court.







-4.webp?w=1000&h=1000&fit=crop&crop:edges)

