MalwareRansomwareData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Professional Finance Company
bd_fef912feb56f7681 · schema v1 · pii pii-v1
Full breach record for Professional Finance Company →Professional Finance Company, Inc. experienced a ransomware attack on February 26, 2022, where an unauthorized third party accessed and disabled computer systems. The incident exposed personal information including names, addresses, social security numbers, and accounts receivable/payment data. The company engaged forensic investigators, rebuilt systems, and offered credit monitoring to affected individuals.
California clockDiscovered Feb 26, 2022 → Notified Jul 1, 2022125d ✗ CA 60-day late18 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_640d80038ee00b12Maine State AGfiled 2022-07-01Verified
- bd_8650c05ef2646cb8Montana State AGfiled 2022-07-01Verified
- bd_b584044d590b69d4HHS OCRfiled 2022-07-01Verified
- bd_befcd16a7ae82f82Washington State AGfiled 2022-07-01Verified
Show 2 more filings ↓Show fewer ↑up to 45d gap
- bd_e9316ef5dce5f05cOregon State AGfiled 2022-07-01Verified
- bd_426f675f0ed006b7Montana State AGfiled 2022-05-17(45d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-554844
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 1, 2022
- Raw hash
- 00d7f1e89d6dc3aac6eb469a57f8c7a2a59300d59dd35091096aa18ccc86c305
Reporting entity
- Name
- Professional Finance Companynorm: professional finance
Victim entity
- Name
- Professional Finance Companynorm: professional finance
Incident
- Discovered
- Feb 26, 2022
- Materiality determined
- —
- Notification sent
- Jul 1, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 18 weeks(125 days from discovery to filing)
- Compliance flags
- CA 60-day late · 125d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 26, 2022→ Notified: Jul 1, 2022125d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.