Drooid Logo
Back to story perspectives

Full Breakdown

M&A Lawyer Nicolo Nourafchan Charged in Massive Insider-Trading Scheme Highlights Law-Firm Document Security Gaps

6/3/2026, 10:02:01 PM

Alleged Insider-Trading Scheme and Criminal Charges

Former M&A attorney Nicolo Nourafchan, who practiced at Latham & Watkins, Goodwin Procter and Sidley Austin, pleaded not guilty on June 1 at the John Joseph Moakley United States Courthouse in Boston. Federal prosecutors allege he led a ring that generated tens of millions of dollars in illegal profits by trading on confidential merger information. Around 30 individuals—including his brother Lorenzo Nourafchan and co-defendant Gabriel Gershowitz—have been charged in USA v. Nourafchan (1:26-cr-10115) and SEC v. Nourafchan (1:26-cv-12068).

How Confidential Deal Information Was Accessed

The SEC complaint says Nourafchan used his firm’s document-management system to search for keywords, preview files and view documents in read-only mode, minimizing electronic footprints. He allegedly obtained material on roughly a dozen transactions for which he was not assigned, including deals coded “Project Mars,” “Flying Cloud” and “Project Integrator.” The scheme spanned roughly fifteen years; Gershowitz supplied tips, and an unnamed attorney from Wachtell Lipton Rosen & Katz also leaked information, though no charge has been filed against that individual.

Key Figures and Law Firms Involved

The alleged conspirators include: Nicolo Nourafchan (Yale Law Class of 2011); Gabriel Gershowitz, a former associate at Weil Gotshal & Manges, Willkie Farr & Gallagher and DLA Piper, who has pleaded guilty and is cooperating; Lorenzo Nourafchan; and more than a dozen other attorneys from Goodwin Procter, Sidley Austin, Weil Gotshal & Manges, Willkie Farr & Gallagher, DLA Piper and Wachtell Lipton Rosen & Katz. All firms declined comment on the investigation.

Impact on Law-Firm Document Management Practices

The case has drawn attention to the vulnerability of internal document systems that prioritize collaboration over strict access controls. Legal experts predict firms will adopt tighter authentication, monitoring of anomalous behavior, and granular permission settings to prevent unauthorized viewing of client files. The exposure of these flaws may prompt broader industry standards for data security.

Official Statements & Responses

Nourafchan’s counsel, Martin Weinberg, said his client “asserts his innocence as to all charges” and will mount a vigorous defense. Christopher Ehrman, former CFTC whistleblower-office director, warned that firms “cannot just have data there but then not secure it.” UCLA law professor Scott Cummings noted that “if someone really wants to gain access to other client information, they can.” Integris vice-president David D’Agostino recommended that firms “identify who has access, limit that access, and monitor for anomalous and suspicious behavior,” adding that after-hours logins should trigger alerts.

Criticism & Opposition

Cybersecurity specialists argue that the lack of real-time monitoring and insufficient segregation of duties created an environment ripe for abuse. Scott Cummings emphasized that existing safeguards are “highly irresponsible” when they allow unrestricted file access. Observers contend that reliance on code-named projects without robust authentication undermines client confidentiality.

Verbatim Quotes

  • “Nicolo Nourafchan asserted his innocence as to all charges during yesterday’s arraignment,” — Martin Weinberg, attorney
  • “You can’t just have data there but then not secure it,” — Christopher Ehrman, former CFTC whistleblower-office director
  • “If someone really wants to gain access to other client information, they can,” — Scott Cummings, UCLA School of Law professor
  • “identify who has access, and limit that access, and then monitor for anomalous and suspicious behavior,” — David D’Agostino, Integris vice-president
  • “Behavior such as logging in after hours, or accessing or moving certain files, should “potentially trigger a notification and alert that would require investigation,” he said.” — David D’Agostino, Integris vice-president

Conflicting Reports & Gaps

The indictment mentions an unnamed Wachtell Lipton Rosen & Katz attorney who allegedly leaked information, yet no charges have been filed against that individual. Law firms involved have not provided substantive comments, leaving the extent of internal policy failures unclear.

What’s Next

The criminal cases are slated for trial later this year, and the SEC civil action proceeds concurrently. Law-firm clients and regulators are watching for potential reforms to document-management security protocols as the proceedings unfold.