Professional Finance Company Inc.
| Primary URL | Location | Industry | pfc[.]com |
Country
United States of America
|
Financial Services
|
|---|
Profile
Professional Finance Company Inc., which also trades under the alias PFC, is a financial services provider headquartered in the United States. The organization identifies itself as a debt collections firm, concentrating its operations on the healthcare sector while also serving clients in other industries. Its primary service offering involves the management of accounts receivable, including the collection of outstanding payments on behalf of healthcare providers. In addition to collections, PFC provides payment processing solutions that help clients streamline billing and revenue cycles. The company’s client base consists of numerous healthcare organizations ranging from hospitals to outpatient clinics across the United States. By handling financial transactions for these entities, PFC routinely processes personal and financial data that belongs to patients. This data handling includes information such as patient names, contact details, insurance identifiers, and billing amounts. The firm’s operations therefore place it in a position where it must safeguard sensitive information as part of its routine business activities.
On February 23, 2022, Professional Finance Company Inc. was targeted by a ransomware attack attributed to the Quantum ransomware group, which has ties to Conti cybercrime affiliates. The attackers gained initial access to PFC’s network using the Cobalt Strike penetration‑testing toolkit before moving laterally within the environment. Prior to deploying the ransomware payload, the threat actors exfiltrated a substantial volume of data from the company’s systems. The compromised data set encompassed information belonging to more than 600 healthcare organizations that are clients of PFC. According to breach disclosures, the incident affected roughly 1.9 million individual patients and 657 distinct healthcare providers. The exfiltrated records included personally identifiable information such as names, mailing addresses, telephone numbers, and Social Security numbers. In addition to identifiers, the stolen data contained financial details, birth dates, and, in some cases, specific medical treatment information. Following the discovery of the breach, PFC issued notification letters to the affected individuals and offered them complimentary credit monitoring services. The episode underscored the nature of PFC’s business as a handler of protected health information and highlighted the security risks inherent in managing such data for healthcare clients.
