HackingData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICBIOMETRICMediumActive
Phillip Galyen, PC
bd_58c3bdd5464ace6e · schema v1 · pii pii-v1
Full breach record for Phillip Galyen, PC →Phillip Galyen, PC reported a potential data security incident in March 2021 where unauthorized access to its network may have exposed client and employee personal information, including names, SSNs, driver's licenses, financial data, and medical/biometric records. The firm engaged forensic investigators, notified the FBI, and is offering credit monitoring services. The investigation was ongoing as of the May 14, 2021 notification.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_2daa36d5127aab09California State AGfiled 2021-05-14Verified
- bd_4819f57bea082e64Maine State AGfiled 2021-05-14Verified
- bd_b7d34ac9fee95be4Oregon State AGfiled 2021-05-14Verified
- bd_ba4e0807d5f67f56Montana State AGfiled 2021-05-14Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_5be7503d6ad65fc0Delaware State AGfiled 2021-05-13(1d gap)Candidate
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2021/PhillipGaylen.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 14, 2021
- Raw hash
- af35bdda012c5f2db028ffc10638ef20c3c082b5a43f1fdff3de68f87646eded
Reporting entity
- Name
- Phillip Galyen, PCnorm: phillip galyen
Victim entity
- Name
- Phillip Galyen, PCnorm: phillip galyen
Incident
- Discovered
- Mar 1, 2021
- Materiality determined
- —
- Notification sent
- May 14, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICBIOMETRIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Reported the incident to the Federal Bureau of Investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(74 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.