PHILLIP GALYEN
ent_ed86c41cf68a638d375b21a2
Disclosures
14
State AG · 13 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
12,225
nationwide · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- PHILLIP GALYEN
- Normalized
- phillip galyen— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (14)newest first
- Texas State AGas victim2026-05-22
Phillip Galyen P.C. dba Bailey & Galyen based in Bedford, Texas, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-11-04 and reported on 2026-05-22. 11,038 Texas residents were affected. 12,225 individuals affected in total. Types of information involved: Name of individual;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Medical Information;Health Insurance Information. Consumers were notified via U.S. Mail.
- Vermont State AGas victim2026-05-21
Phillip Galyen P.C. dba Bailey & Galyen reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-05-21. The reporting organization type is Other Commercial. 4 Vermont residents were affected. Categories of data breached: Social Security Numbers.
- Massachusetts State AGas victim2026-05-21
Phillip Galyen P.C. dba Bailey & Galyen, a law firm, notified Massachusetts residents of a data security incident affecting personal information. The notification, dated May 19, 2026, indicates unauthorized access to client data. Affected individuals were offered 24 months of credit monitoring and identity theft protection services via IDX. Specific data types and affected counts were not explicitly quantified in the provided notice text.
- New Hampshire State AGas victim2026-05-20
Bailey & Galyen, a full-service law firm, notified the NH Attorney General that an unknown actor gained unauthorized access to its network on November 4, 2025, and may have downloaded files containing personal information. The incident affected three New Hampshire residents, whose names and Social Security numbers were potentially compromised. The firm engaged external cybersecurity experts, secured its network, and offered 12 months of identity protection services to affected individuals.
- Indiana State AGas victim2026-05-19
Phillip Galyen PC dba Bailey & Galyen reported a data breach to the Indiana Attorney General. The breach occurred on 2025-11-04 and was reported on 2026-05-19. 14 Indiana residents were affected. 12,225 individuals affected in total.
- California State AGas victim2021-05-14
In March 2021, Phillip Galyen PC (a law firm) discovered unusual activity within its network. Investigation revealed a malicious actor may have accessed the network without authorization and may have acquired personal information of clients and employees, including names, dates of birth, driver's license numbers, SSNs, payment card data, biometric data, and medical information. The firm notified the FBI and offered credit monitoring to affected individuals.
- Maine State AGas victim2021-05-14
Phillip Galyen PC reported an external system breach (hacking) occurring on 03/01/2021 and discovered on 04/01/2021. The incident compromised names and financial account/credit card numbers. The number of affected individuals is unknown. Substitute notice was sent on 05/14/2021, and identity theft protection services were offered.
- South Carolina State AGas victim2021-05-14
Phillip Galyen, PC reported a potential data security incident in March 2021 where unauthorized access to its network may have exposed client and employee personal information, including names, SSNs, driver's licenses, financial data, and medical/biometric records. The firm engaged forensic investigators, notified the FBI, and is offering credit monitoring services. The investigation was ongoing as of the May 14, 2021 notification.
- Washington State AGas victim2021-05-14
Phillip Galyen, PC, a Texas law firm, notified the Washington AG of a March 2021 unauthorized network access. Malicious actors may have accessed client and employee PII, including SSNs, driver's licenses, financial data, and PHI. No specific count was provided. The firm engaged forensic investigators, notified the FBI, and offered 12 months of credit monitoring via IDX.
- Oregon State AGas victim2021-05-14
Phillip Galyen PC reported a data breach to the Oregon Attorney General. The breach was reported on 2021-05-14. The breach occurred during 3/1/2021 - 4/1/2021. The breach was discovered on 4/26/2021. 250 individuals were affected. Notice was sent on 5/14/2021.
- Montana State AGas victim2021-05-14
Phillip Galyen, PC notified Montana regulators in May 2021 of a March 2021 unauthorized network access. The incident potentially exposed client and employee PII, including SSNs, driver's licenses, financial data, and PHI. The firm engaged forensic investigators, notified the FBI, and offered credit monitoring.
- Massachusetts State AGas victim2021-05-14
Phillip Galyen PC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-05-14. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Delaware State AGas victim2021-05-13
Phillip Galyen, PC notified Delaware AG on May 14, 2021, of a March 2021 unauthorized network access. Malicious actors may have accessed client and employee data including names, SSNs, driver's licenses, financial account numbers, and medical/biometric records. Galyen hired forensic investigators, notified the FBI, and offered credit monitoring. No specific count of affected individuals was disclosed.
- Illinois State AGas victim2021-01-01
PHILLIP GALYEN filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-174). The register records the breach as discovered on March 1, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.