BFC Solutions, preventive maintenance services provider for commercial HVAC systems, has experienced a data breach affecting thousands of individuals across the United States. The cybersecurity incident occurred following a network disruption that took place between June 18, 2024, and June 20, 2024.
An investigation determined that unauthorized actors gained access to certain BFC Solutions systems and both personally identifiable information (PII) and protected health information (PHI) were compromised. Exposed information includes names, dates of birth, Social Security numbers, driver's license or state ID numbers, health insurance information, medical information and financial information.
BFC Solutions disclosed the data breach to the Maine, Massachusetts and Texas Attorney Generals' offices beginning on Aug. 14, 2025. The cybersecurity incident impacted at least 8,371 individuals, including 838 Texas residents, 100 in Massachusetts and 14 in Maine.
The breadth of information accessed, including both PII and PHI, raises the risk of identity theft, financial fraud and medical identity theft. The company began notifying affected individuals on Aug. 14, 2025.
BFC Solutions is offering complimentary credit monitoring, credit reports and credit score services for 12 months through Cyberscout, a TransUnion company. These services include alerts for changes to credit files, as well as proactive fraud assistance and remediation support.
If you receive a data breach notice from BFC Solutions, you may want to:
For more information about the company, visit BFC Solutions’ website.
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.