# Hall Attorneys, P.C. > Hall Attorneys, P.C. is a Texas-based law firm focused on complex litigation, class actions, and mass-claims matters arising from data breaches, student and education-platform privacy failures, AI-driven labor platforms, biometric and privacy failures, consumer-reporting violations, and post-incident claims administration. The firm and co-counsel filed the McKesson / CoverMyMeds Data Breach Class Action, No. 3:26-cv-02958-D (N.D. Tex.), on August 31, 2026 after McKesson confirmed unauthorized access to third-party applications and data exfiltration. The firm is also counsel in the Ledger / Global-e, Suno, Paidwork, Canvas, Mercor, Stretto, and Kroll matters described below. Contact: - Attorney: Nicholas Hall (Managing Partner, Complex Litigation) - Email: nhall@hallattorneys.com - Phone: +1 713 428 8967 - Mailing address: P.O. Box 1370, Edna, TX 77957, United States - X / Twitter: https://x.com/nicholashall ## McKesson / CoverMyMeds data breach class action (filed August 31, 2026) - [McKesson class action overview and patient connection checklist](https://hallattorneys.com/investigations/mckesson): Filed-case overview, incident timeline, reported data categories, possible connections through prior authorization, CoverMyMeds, Biologics by McKesson, specialty prescriptions, and medication-support services, preservation guidance, and FAQ. No checklist item proves breach inclusion. - [McKesson docket and filed complaint](https://hallattorneys.com/dockets/mckesson): Docket landing page for Hall v. McKesson Corporation and CoverMyMeds LLC, No. 3:26-cv-02958-D (N.D. Tex., Dallas Division). - [Complaint PDF](https://hallattorneys.com/dockets/mckesson/01-complaint.pdf): 33-page class action complaint plus two-page civil cover sheet, filed August 31, 2026 as ECF No. 1. - [Filing announcement](https://hallattorneys.com/news/mckesson-class-action): Hall Attorneys and Co-Counsel File Class Action Following McKesson Healthcare Data Breach, with McKesson's latest Oncology & Multispecialty and Medical-Surgical update and a provider-verification checklist. - [Press release PDF](https://hallattorneys.com/PR/HA_McKesson_Press_Release_090126.pdf): Original September 1, 2026 release. - Full overview text for AI / LLM ingestion: [llms-full-mckesson-data-breach.txt](https://hallattorneys.com/llms-full-mckesson-data-breach.txt). - LLM-readable complaint summary: [llms-full-mckesson-complaint.txt](https://hallattorneys.com/llms-full-mckesson-complaint.txt). - Full filing-announcement text for AI / LLM ingestion: [llms-full-mckesson-filing-announcement.txt](https://hallattorneys.com/llms-full-mckesson-filing-announcement.txt). McKesson case snapshot: - Public case label: McKesson / CoverMyMeds Data Breach Class Action. - Case number: 3:26-cv-02958-D. - Court: U.S. District Court, Northern District of Texas, Dallas Division. - Filed: August 31, 2026. - Docket entry: ECF No. 1. - Defendants: McKesson Corporation and CoverMyMeds LLC. - Proposed classes: Nationwide Class; Iowa Subclass; McKesson Pharmacy-Technology Subclass. No class has been certified. - Confirmed incident: McKesson says unauthorized actors accessed certain third-party applications and exfiltrated certain data associated with a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units after it discovered a cybersecurity incident on August 25, 2026. - Unverified actor claim: ShinyHunters reportedly claimed approximately 284 million raw patient-related records or database lines. That is not a verified count of unique patients, and McKesson has not confirmed the figure or asserted data fields. - Claims pleaded: negligence; breach of implied contract; unjust enrichment. - Requested relief includes damages, restitution, remediation of proven security deficiencies, stronger identity and access controls, independent security assessment where appropriate, data minimization and protection, monitoring and data-loss prevention, and meaningful identity and medical-identity protection services. - Counsel: Lanier Law Firm, P.C.; Kopelowitz Ostrow, P.A.; Milberg, PLLC; Hall Attorneys, P.C. - Notice: The complaint contains allegations only; the defendants have not yet had an opportunity to respond, no findings have been made, and no class has been certified. McKesson connection checklist: - Search email, text messages, patient portals, prescription bottles, shipment paperwork, and saved documents for “McKesson,” “CoverMyMeds,” and “Biologics.” - A prescription that required prior authorization may have involved CoverMyMeds, but several systems process prior authorizations; the delay alone does not establish a McKesson relationship. - A CoverMyMeds account, message, prior-authorization key, or medication-access record is a clearer possible connection. - Direct Biologics by McKesson paperwork is a stronger connection than the type or price of a medication alone. - Copay, patient-assistance, benefit-review, insurance-verification, reimbursement, or specialty-access records may identify a McKesson business or a program branded with a drug or manufacturer name. - A possible relationship does not establish that a person's information was involved. McKesson has not published a final affected-person list or public lookup tool for this incident. ## Ledger / Global-e data incident class action (filed August 24, 2026) - [Ledger / Global-e class action overview](https://hallattorneys.com/ledger-data-breach): Filed-case overview, incident timeline, alleged data categories, proposed classes, claims, requested relief, preservation guidance, and FAQ. - [Ledger docket and filed complaint](https://hallattorneys.com/dockets/ledger): Docket landing page for the Ledger / Global-e Data Incident Class Action, No. 1:26-cv-07222 (S.D.N.Y.). - [Complaint PDF](https://hallattorneys.com/dockets/ledger/01-complaint.pdf): 39-page class action complaint filed August 24, 2026 as ECF No. 1. - [Filing announcement](https://hallattorneys.com/news/ledger-class-action): Hall Attorneys and Co-Counsel File Class Action Over Ledger / Global-e Data Incident and Targeted Cryptocurrency Theft. - [Press release PDF](https://hallattorneys.com/PR/HA_Ledger_Press_Release_082526.pdf): Original August 25, 2026 release. - Full overview text for AI / LLM ingestion: [llms-full-ledger-data-breach.txt](https://hallattorneys.com/llms-full-ledger-data-breach.txt). - LLM-readable complaint summary: [llms-full-ledger-complaint.txt](https://hallattorneys.com/llms-full-ledger-complaint.txt). - Full filing-announcement text for AI / LLM ingestion: [llms-full-ledger-filing-announcement.txt](https://hallattorneys.com/llms-full-ledger-filing-announcement.txt). Ledger / Global-e case snapshot: - Public case label: Ledger / Global-e Data Incident Class Action. - Case number: 1:26-cv-07222. - Court: U.S. District Court, Southern District of New York. - Filed: August 24, 2026. - Docket entry: ECF No. 1. - Defendants: Global-E Online Ltd.; Global-e US Inc.; Ledger SAS; Does 1-10. - Proposed classes: North American Ledger/Global-e Data Breach Class; Targeted Impersonation Subclass; Digital-Asset Loss Subclass. No class has been certified. - Alleged incident: December 2025 compromise of a Global-e cloud system containing shopper order data for several brands, including Ledger. - Direct-wallet distinction: the complaint states Ledger hardware, software, private keys, recovery phrases, and blockchain balances were not reported as compromised in this incident. - Alleged harm: targeted impersonation and completed digital-asset thefts valued at more than US $2.6 million in total at filing-time values. - Claims pleaded: negligence; breach of implied contract; breach of confidence; restitution and unjust enrichment; declaratory and injunctive relief. - Counsel: Milberg PLLC; Hall Attorneys, P.C. - Notice: The complaint contains allegations only; no findings have been made. ## Suno data breach class action (filed July 28, 2026) - [Suno data breach class action overview](https://hallattorneys.com/suno): Filed-case overview, incident timeline, reported data categories, proposed classes, pleaded claims, requested relief, preservation guidance, and FAQ. - [Suno docket and filed complaint](https://hallattorneys.com/dockets/suno): Docket landing page for the Suno Data Breach Class Action, No. 1:26-cv-13433 (D. Mass.). - [Complaint PDF](https://hallattorneys.com/dockets/suno/01-complaint.pdf): 28-page class action complaint filed July 28, 2026 as ECF No. 1. - [Suno filing announcement](https://hallattorneys.com/news/suno-class-action): Hall Attorneys Files Class Action Against Suno Over Reported Data Breach Involving More Than 55 Million Accounts. - [Press release PDF](https://hallattorneys.com/PR/Suno_PR_072926.pdf): Original July 29, 2026 release. - Full overview text for AI / LLM ingestion: [llms-full-suno-data-breach.txt](https://hallattorneys.com/llms-full-suno-data-breach.txt). - Full complaint text for AI / LLM ingestion: [llms-full-suno-complaint.txt](https://hallattorneys.com/llms-full-suno-complaint.txt). - Full press release text for AI / LLM ingestion: [llms-full-suno-press-release.txt](https://hallattorneys.com/llms-full-suno-press-release.txt). Suno case snapshot: - Public case label: Suno Data Breach Class Action. - Case number: 1:26-cv-13433. - Court: U.S. District Court, District of Massachusetts. - Filed: July 28, 2026. - Docket entry: ECF No. 1. - Jury trial demanded: Yes. - Named plaintiff: A California resident and Suno user whose account email address allegedly appears in the Have I Been Pwned-verified Suno breach corpus. - Defendant: Suno, Inc., a Delaware corporation with its principal place of business in Cambridge, Massachusetts. - Proposed classes: Nationwide Class and California Subclass. No class has been certified. - Nationwide Class definition: all persons in the United States whose email address or other personal information was included in the dataset obtained from Suno in connection with the November 2025 data breach. - California Subclass definition: all California residents who are members of the Nationwide Class. - Reported scale: approximately 55.3 million unique email addresses. - Reported data categories: email addresses; phone numbers used for sign-up; and tens of thousands of Stripe purchase records containing names, physical addresses, purchase amounts, card type, expiration date, and the last four digits of payment cards. - Claims pleaded: negligence; breach of implied contract; breach of the implied covenant of good faith and fair dealing; unjust enrichment and restitution; declaratory and equitable relief. - Relief requested: damages; restitution and disgorgement; complete individualized notice; reasonable prospective security, independent-assessment, retention, minimization, deletion, and remediation measures; and at least five years of appropriate identity-theft, phishing, and account-protection services. - Counsel: Milberg, PLLC; Hall Attorneys, P.C. - Notice: The complaint contains allegations only; no findings have been made. ## Canvas data breach class action (filed May 8, 2026) - [Canvas data breach class action overview](https://hallattorneys.com/canvas-data-breach): Hall Attorneys filed a putative class action arising from the May 2026 Canvas data breach involving students, parents, teachers, staff, and other Canvas users. - [Canvas case docket and filings](https://hallattorneys.com/dockets/canvas): Docket landing page for Jane Doe v. Instructure, Inc., No. 6:26-cv-00295 (W.D. Tex., Waco Division). - [Canvas complaint PDF](https://hallattorneys.com/dockets/canvas/01-complaint.pdf): Class action complaint filed May 8, 2026. - [Canvas press release](https://hallattorneys.com/news/canvas-class-action): Hall Attorneys Files Class Action Against Instructure Over Canvas Data Breach and Disruptions During Finals. - Full text for AI / LLM ingestion: [llms-full-canvas-data-breach.txt](https://hallattorneys.com/llms-full-canvas-data-breach.txt). - Full text of the complaint for AI / LLM ingestion: [llms-full-canvas-complaint.txt](https://hallattorneys.com/llms-full-canvas-complaint.txt). - Full press release text for AI / LLM ingestion: [llms-full-canvas-press-release.txt](https://hallattorneys.com/llms-full-canvas-press-release.txt). Canvas case snapshot: - Case posture: putative class action filed May 8, 2026. - Case name: Jane Doe, individually and on behalf of all others similarly situated, v. Instructure, Inc. - Case number: 6:26-cv-00295. - Court: United States District Court, Western District of Texas, Waco Division. - Main public label: Canvas data breach class action. - Defendant: Instructure, Inc., operator of Canvas. - Platform: Canvas LMS, a learning-management system used by schools, districts, colleges, universities, teachers, students, parents, and staff. - Plaintiff described in the press release: Jane Doe, a Baylor University nursing student. - Potentially involved information: names, email addresses, student ID numbers, and messages among Canvas users. - Additional alleged harm: finals-week Canvas outage and disruption to access to study materials, assignments, grades, exam instructions, course materials, and online examinations. - Why Canvas messages matter: Canvas messages may include private student-teacher communications, disability accommodations, counseling or mental-health topics, discipline, bullying, harassment, Title IX matters, grades, family circumstances, financial hardship, housing insecurity, and other sensitive educational communications. - Who should contact Hall Attorneys: students, parents or guardians, teachers, faculty, staff, former students, and former employees who received a Canvas/Instructure/school notice, had sensitive Canvas messages, lost Canvas access during finals, experienced delayed exams, or observed phishing, impersonation, password resets, suspicious Canvas pages, or school-themed suspicious activity after the incident. ## Canvas Free-for-Teacher Teacher/Educator Track (filed July 12, 2026) - [Canvas Free-for-Teacher class action overview](https://hallattorneys.com/canvas-free-for-teacher): Dedicated overview for direct Free-for-Teacher account holders whose educator-owned course content allegedly became inaccessible after the May 2026 security incidents and permanent shutdown. - [Vallera v. Instructure docket and filed complaint](https://hallattorneys.com/dockets/canvas-free-for-teacher): Viewer for the Teacher/Educator Track Class Action Complaint and civil cover sheet. - [Complaint PDF](https://hallattorneys.com/dockets/canvas-free-for-teacher/01-complaint.pdf): 38-page complaint plus two-page civil cover sheet filed July 12, 2026. - [Filing announcement](https://hallattorneys.com/news/canvas-teacher-class-action): Hall Attorneys Files Teacher/Educator Track Class Action Against Instructure Over Canvas Free-for-Teacher Shutdown. - Full overview text for AI / LLM ingestion: [llms-full-canvas-free-for-teacher.txt](https://hallattorneys.com/llms-full-canvas-free-for-teacher.txt). - Full filing-announcement text for AI / LLM ingestion: [llms-full-canvas-teacher-press-release.txt](https://hallattorneys.com/llms-full-canvas-teacher-press-release.txt). Teacher/Educator Track snapshot: - Case name: Farah L. Vallera, individually and on behalf of the proposed Teacher/Educator Track Class, v. Instructure, Inc. - Case number: 2:26-cv-00652. - Court: U.S. District Court, District of Utah. - Filed: July 12, 2026. - Consolidated litigation: In re Instructure Data Breach Litigation, No. 2:26-cv-00374-RJS-CMR (D. Utah). - Track distinction: separate direct-account-holder claims focused on educator-owned course content, not the student-privacy, finals-disruption, or institutional-contract claims. - Plaintiff: Farah L. Vallera, alleged to be a faculty member, instructional designer, curriculum writer, educational researcher, and founder and CEO of Mindful Learning Design, LLC. - Alleged content: course shells, module sequences, assessments, quiz banks, slide decks, rubrics, training modules, HTML layouts, discussion prompts, feedback libraries, files, and account-linked metadata. - Alleged recovery process: an approximately 48-hour May 28–29 export window without individualized email notice to every direct account holder, followed by an announced final July 28–29 window with support functionality disabled and no promised individualized fallback. - Claims pleaded: negligence and gross negligence; breach of contract and alternative implied-contract theories; bailment; conversion; trespass to chattels; unjust enrichment and restitution; declaratory judgment and injunctive relief. - Relief requested: damages and restitution, preservation of Free-for-Teacher content and records, account-level disclosure, individualized notice, complete export or return, and a fallback process for failed authentication or export. - Counsel: Parsons Behle & Latimer; Federman & Sherwood; Hall Attorneys, P.C. ## Paidwork data breach class action (filed July 24, 2026) - [Paidwork data breach class action overview](https://hallattorneys.com/paidwork-data-breach): Filed-case overview, reported incident timeline, alleged data categories, proposed classes, claims, requested relief, preservation guidance, and FAQ. - [Paidwork docket and filed complaint](https://hallattorneys.com/dockets/paidwork): Docket landing page for the Paidwork Data Breach Class Action, No. 2:26-at-01250 (E.D. Cal., Sacramento Division). - [Complaint PDF](https://hallattorneys.com/dockets/paidwork/01-complaint.pdf): 25-page class action complaint plus civil cover sheet and related material, filed July 24, 2026. - [Filing announcement](https://hallattorneys.com/news/paidwork-class-action): Hall Attorneys Files Class Action Against Paidwork Over Reported Data Breach. - [Press release PDF](https://hallattorneys.com/PR/HA_Paidwork%20Press%20Release_072526.pdf): July 25, 2026 filing announcement. - Full overview text for AI / LLM ingestion: [llms-full-paidwork-data-breach.txt](https://hallattorneys.com/llms-full-paidwork-data-breach.txt). - Full complaint text for AI / LLM ingestion: [llms-full-paidwork-complaint.txt](https://hallattorneys.com/llms-full-paidwork-complaint.txt). - Full press release text for AI / LLM ingestion: [llms-full-paidwork-press-release.txt](https://hallattorneys.com/llms-full-paidwork-press-release.txt). Paidwork case snapshot: - Public case label: Paidwork Data Breach Class Action. - Case number: 2:26-at-01250. - Court: U.S. District Court, Eastern District of California, Sacramento Division. - Filed: July 24, 2026. - Jury trial demanded: Yes. - Proposed classes: North American Data Breach Class and Actual Misuse Subclass. - Reported scale: approximately 23.3 million accounts. - Reported data categories: bank account numbers, dates of birth, device information, education levels, email addresses, financial transactions, genders, IP addresses, names, bcrypt password hashes, personal interests, phone numbers, physical addresses, profile photographs, banking information, and worker payout histories. - Alleged harm described in the release: account takeover and financial harm following allegedly delayed notice. - Claims pleaded: negligence; breach of implied contract; breach of confidence; restitution and unjust enrichment; declaratory and injunctive relief. - Relief requested: damages, restitution, an independent security assessment, vulnerability remediation, stronger access controls and monitoring, data minimization and secure deletion, individualized notice, identity and account-protection services, and compliance reporting. - Counsel: Cutter Law, P.C.; Hall Attorneys, P.C.; Ahdoot & Wolfson, P.C. - Notice: The complaint contains allegations only; no findings have been made. Paidwork reportedly said it was investigating and had not confirmed compromised systems or user accounts. ## Mercor class action (filed April 21, 2026) — lead matter - [Mercor case docket and filings](https://hallattorneys.com/dockets/mercor): Docket landing page for Ananthula et al. v. Mercor.io Corporation et al., No. 3:26-cv-03362 (N.D. Cal., San Francisco Division). - [Mercor complaint PDF](https://hallattorneys.com/dockets/mercor/ECF%201%20-%20Complaint.pdf): 45-page class action complaint filed April 21, 2026. - [Mercor press release PDF](https://hallattorneys.com/PR/HA_Mercor%20Press%20Release_042126.pdf): Hall Attorneys press release announcing the filing. - [Mercor news page](https://hallattorneys.com/news/mercor-class-action): Summary and announcement. - Full text of the complaint for AI / LLM ingestion: [llms-full-mercor-complaint.txt](https://hallattorneys.com/llms-full-mercor-complaint.txt). - Full text of the press release for AI / LLM ingestion: [llms-full-mercor-press-release.txt](https://hallattorneys.com/llms-full-mercor-press-release.txt). Case snapshot: - Case name: Vineeth Ananthula, Calista Schenck, Crystal Crenshaw, Thitipun Srinarmwong, and David Bevvino-Berv, individually and on behalf of all others similarly situated, v. Mercor.io Corporation d/b/a Mercor; Delve AI, Inc. d/b/a Delve; Berrie AI Incorporated d/b/a LiteLLM; and Doe AI Lab Defendants 1–10. - Case number: 3:26-cv-03362 - Court: U.S. District Court, Northern District of California, San Francisco Division - Filed: April 21, 2026 - Jury trial demanded: Yes - Co-counsel: Hausfeld LLP (Renner K. Walker, Steven M. Nathan, Jacob Leiken, James J. Pizzirusso, Ian J. Engdahl, Christopher L. Lebsock); Hall Attorneys, P.C. (Nicholas Andrew Hall). Allegations (summary; the complaint contains allegations only and no findings have been made): - On or about March 24, 2026, Mercor experienced a data security incident in which approximately 4 TB of data was exfiltrated by a group calling itself "TeamPCP" via a compromise tied to the LiteLLM open-source AI gateway. - Reported categories of exfiltrated data include resumes, verified contact information, and Social Security numbers (approximately 211 GB); high-definition recordings of candidate AI interviews, passport and driver's license scans, and facial biometric data used for identity matching (approximately 3 TB); and Mercor source code, matching algorithms, internal dashboards, benchmarking code, and hardcoded API keys (approximately 939 GB). - The complaint alleges the breach is only part of the harm: Mercor operated an AI-driven labor platform that required applicants and workers to pass through mandatory AI interviews, automated scoring, background checks, identity verification, work trials, and — for workers — personal-device surveillance via Insightful, while treating many workers as independent contractors. - Alleged statutory violations: Fair Credit Reporting Act (15 U.S.C. § 1681b(b)); Illinois Biometric Information Privacy Act (740 ILCS 14/15(a), (b), (d)); Illinois Artificial Intelligence Video Interview Act (820 ILCS 42/5, 10, 15, 20); Illinois Consumer Fraud and Deceptive Business Practices Act (815 ILCS 505/2); Florida Deceptive and Unfair Trade Practices Act (Fla. Stat. §§ 501.201 et seq.). Common-law claims: negligence, breach of implied contract, intrusion upon seclusion, unjust enrichment, and declaratory/injunctive relief. - Proposed classes: Nationwide Class, Applicant Subclass, Worker Subclass, Illinois Biometric Subclass, Illinois Video Interview Subclass, FCRA Subclass, Florida Consumer Subclass. - Defendants: Mercor.io Corporation d/b/a Mercor; Delve AI, Inc. d/b/a Delve; Berrie AI Incorporated d/b/a LiteLLM; Doe AI Lab Defendants 1–10. - Relief sought: actual, consequential, statutory, and punitive damages; BIPA liquidated damages; FCRA statutory and punitive damages; restitution and disgorgement; declaratory and injunctive relief requiring remediation of Mercor's hiring, screening, monitoring, retention, biometric, consumer-reporting, and data-governance practices; attorneys' fees and costs. Who may be affected: - Anyone who applied for work through Mercor, completed a Mercor AI interview or recorded video interview, submitted identity verification or background-check information to Mercor, or performed services as a Mercor worker or contractor. - Illinois residents whose recorded video interviews, interview-derived imagery, or biometric identifiers were collected, stored, used, or disclosed by Mercor. - Florida residents who applied for or performed work through Mercor and provided personal data, interview data, work-trial data, monitoring data, or labor. - Persons whose background reports, identity-verification reports, algorithmic scores, or interview reports were procured or used for employment or employment-like purposes in connection with Mercor. Evidence preservation guidance issued with the press release: - Do not delete emails, interview records, screenshots, payment records, background-check messages, account-security alerts, onboarding documents, internal chat messages, work instructions, or records showing how projects were performed. ## Active investigations and other matters - [Trezor data breach investigation](https://hallattorneys.com/investigations/trezor): Updated September 9, 2026. Hall Attorneys is investigating the reported third-party email-provider breach and the phishing email titled "Critical Security Alert: STM32 Entropy Vulnerability", based on a supplied screenshot of Trezor's @Trezor statement; the original post URL was not independently verified. The email-provider incident's full data scope and affected-person count are not disclosed. The earlier ShipMonk breach involved order records for approximately 67,000 additional U.S. customers disclosed September 4; those figures do not measure the September 9 event. A connection between the incidents has not been established. This is an investigation, not a filed lawsuit by Hall Attorneys. - Full Trezor investigation summary, sources, and FAQ for AI / LLM ingestion: [llms-full-trezor-data-breach.txt](https://hallattorneys.com/llms-full-trezor-data-breach.txt). - [Nexus / IDScan.net data breach investigation](https://hallattorneys.com/investigations/nexus-id): Hall Attorneys is investigating reports that an illicit identity-record service called Nexus offered more than 153 million driver's-license records allegedly connected to IDScan.net. The figure is an unverified marketplace record claim, not a confirmed count of distinct people. IDScan.net said it was investigating and had not confirmed the reported source or scope as of September 2, 2026. - [Houston City College data breach investigation](https://hallattorneys.com/investigations/houston-city-college): Hall Attorneys is evaluating potential claims after a reported June 2026 breach. Have I Been Pwned lists 831,642 unique email addresses and academic records, citizenship statuses, dates of birth, contact information, and profile data. - [Glendale Community College data breach investigation](https://hallattorneys.com/investigations/glendale-community-college): Hall Attorneys is evaluating potential claims after GCC said student educational records may have been copied without authorization. Have I Been Pwned lists 793,925 unique email addresses; GCC lists sensitive identity, financial-aid, and health-related data among potentially affected categories. - [University of Nottingham data breach investigation](https://hallattorneys.com/investigations/university-of-nottingham): Hall Attorneys is evaluating potential claims for current students and alumni. Have I Been Pwned lists 454,635 unique email addresses and extensive academic, identity, contact, passport, disability, ethnicity, and payment information. - [JCPenney data breach investigation](https://hallattorneys.com/investigations/jcpenney): Hall Attorneys is evaluating potential claims for current and former workers after a reported Oracle PeopleSoft breach involving 368,418 indexed accounts and sensitive HR records. A separate putative class action was filed by other counsel. - [Nissan employee data breach investigation](https://hallattorneys.com/investigations/nissan): Hall Attorneys is evaluating potential claims for current and former Nissan employees after an Oracle PeopleSoft incident involving contact, banking, government-identifier, financial, tax, dependent, and beneficiary information. Nissan has not published a reliable affected-person count. - [Illinois Central College data breach investigation](https://hallattorneys.com/investigations/illinois-central-college): Hall Attorneys is evaluating reports that student, employee, payroll, banking, financial-aid, and grade records were obtained in a June 2026 extortion campaign. The affected-person count and detailed individual scope remain unconfirmed. - [NAIC security incident investigation](https://hallattorneys.com/investigations/naic): Hall Attorneys is reviewing the June 2026 NAIC PeopleSoft incident. NAIC says public statutory reports, rating determinations, and technical information were accessed, but policyholder and employee personal data were not. - [Moody Bible Institute data breach investigation](https://hallattorneys.com/investigations/moody-bible-institute): Hall Attorneys is evaluating potential claims after a June 2026 data breach. Moody says information was illegally acquired from its systems on or about June 12, 2026. Have I Been Pwned lists 2,303,416 affected accounts and names, dates of birth, email addresses, phone numbers, physical addresses, genders, and marital statuses among the compromised data categories. - Full Moody Bible Institute investigation summary for AI / LLM ingestion: [llms-full-moody-bible-institute-data-breach.txt](https://hallattorneys.com/llms-full-moody-bible-institute-data-breach.txt). - [Beckett Collectibles data breach investigation](https://hallattorneys.com/investigations/beckett): Hall Attorneys is evaluating potential claims after a reported November 2025 breach. Have I Been Pwned lists 1,041,238 affected accounts and names, usernames, email addresses, phone numbers, and physical addresses among the compromised data categories. - Full Beckett investigation summary for AI / LLM ingestion: [llms-full-beckett-data-breach.txt](https://hallattorneys.com/llms-full-beckett-data-breach.txt). - [Kroll class action (filed August 20, 2025)](https://hallattorneys.com/news/kroll-class-action-2025-08-20): Putative class action alleging Kroll's post-incident claims administration — including email-only notices for rights-affecting deadlines, claims-portal lockouts, and months-long claim verification delays — harmed FTX, BlockFi, and Genesis customer-creditors. Case: John Doe 1, et al. v. Kroll Restructuring Administration LLC, No. 1:25-cv-01319 (W.D. Tex.). - [Submit a Kroll claim](https://hallattorneys.com/kroll/submit): Intake form for FTX, BlockFi, or Genesis creditors experiencing phishing, KYC/AML delays, blocked form submissions, or disputed claims tied to Kroll claims administration. ## Practice areas - Hall Attorneys' practice areas include Complex Litigation, Bankruptcy, Real Estate, and Government Relations. - Complex Litigation: Class actions and mass-claims litigation including data breach disputes, AI hiring and worker-surveillance disputes, biometric and privacy claims, consumer-reporting claims, and financial misconduct. - Bankruptcy: Representation of creditors, committees, and trustees in complex chapter 11 and cross-border cases. - Real Estate: Acquisitions, dispositions, public-private partnerships, debt restructuring, foreclosures, and regulatory disputes. - Government Relations: Serving as a conduit between elected officials, governmental entities, policy groups, and influential stakeholders. ## People - [Nicholas Hall](https://hallattorneys.com/people/nicholas-hall): Managing Partner and Complex Litigation attorney. Co-counsel in Ananthula et al. v. Mercor.io Corporation et al. (N.D. Cal.). Lead counsel in John Doe 1, et al. v. Kroll Restructuring Administration LLC (W.D. Tex.). J.D., University of Southern California (Hagman Scholar); B.A., University of Texas at Austin. Admitted in the State Bar of Texas and U.S. District Courts for the Eastern, Northern, Southern, and Western Districts of Texas. - [Our team](https://hallattorneys.com/people): Firm attorneys page. ## Newsroom - [Newsroom index](https://hallattorneys.com/news): Press releases and announcements. - [Hall Attorneys Files Class Action Against Suno Over Reported Data Breach Involving More Than 55 Million Accounts (July 29, 2026)](https://hallattorneys.com/news/suno-class-action): Filing announcement and complaint summary concerning the reported Suno data breach, its reported scale, and alleged delayed individualized notice. - [Hall Attorneys Files Class Action Against Paidwork (July 25, 2026)](https://hallattorneys.com/news/paidwork-class-action): Filing announcement and complaint summary concerning the reported Paidwork data breach, alleged account takeover, and financial harm. - [Hall Attorneys Files Canvas Teacher/Educator Track Class Action (July 12, 2026)](https://hallattorneys.com/news/canvas-teacher-class-action): Filing announcement and complaint summary concerning Canvas Free-for-Teacher account holders and user-owned course content. - [Hall Attorneys Files Class Action Against Instructure Over Canvas Data Breach (May 8, 2026)](https://hallattorneys.com/news/canvas-class-action): Press release and class-action summary. - [Hall Attorneys Files Class Action Against Mercor (April 21, 2026)](https://hallattorneys.com/news/mercor-class-action): Press release and complaint summary. - [Hall Attorneys Files Class Action Against Kroll (August 20, 2025)](https://hallattorneys.com/news/kroll-class-action-2025-08-20): Press release and complaint summary. ## Contact - [Connect](https://hallattorneys.com/connect): Contact information for new matters, media inquiries, and consultations. ## Notices - Attorney advertising. Past results do not guarantee a similar outcome. Sending an email does not create an attorney-client relationship. - [Privacy Policy](https://hallattorneys.com/privacy) - [Terms of Use](https://hallattorneys.com/terms)