HackingProfessional ServicesProfessional ServicesData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASICBIOMETRICEMPLOYMENTMediumContained
Phillip Galyen, PC
bd_2daa36d5127aab09 · schema v1 · pii pii-v1
Full breach record for Phillip Galyen, PC →In March 2021, Phillip Galyen PC (a law firm) discovered unusual activity within its network. Investigation revealed a malicious actor may have accessed the network without authorization and may have acquired personal information of clients and employees, including names, dates of birth, driver's license numbers, SSNs, payment card data, biometric data, and medical information. The firm notified the FBI and offered credit monitoring to affected individuals.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_4819f57bea082e64Maine State AGfiled 2021-05-14Verified
- bd_58c3bdd5464ace6eSouth Carolina State AGfiled 2021-05-14Verified
- bd_b7d34ac9fee95be4Oregon State AGfiled 2021-05-14Verified
- bd_ba4e0807d5f67f56Montana State AGfiled 2021-05-14Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_5be7503d6ad65fc0Delaware State AGfiled 2021-05-13(1d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-540921
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 14, 2021
- Raw hash
- 1a995f16e6b2caa46b34b3ed687269fd00a889ffdf4000cd138d567e6da6f7e0
Reporting entity
- Name
- Phillip Galyen, PCnorm: phillip galyen
Victim entity
- Name
- Phillip Galyen, PCnorm: phillip galyen
- Industry
- Professional Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASICBIOMETRICEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated CollectionT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Reported incident to the Federal Bureau of InvestigationFiled notification with California Office of the Attorney General
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.