On June 18, 2025, Microf appeared on the leak site of the qilin ransomware group. The company, which provides financing for HVAC systems and water heaters through lease-to-own plans aimed at homeowners with limited credit options, is claimed to have had internal files exfiltrated following a ransomware attack. Public reporting indicates that the number of people whose personal information may have been exposed remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Microf
Get alerted the next time Microf files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Microf’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Breach
Available reporting describes the incident as a ransomware attack in which attackers gained access to Microf’s systems and removed internal documents before encrypting data. The files were later published on the qilin group’s leak site. No confirmed total of affected customer records has been released by the company or independent researchers. The breach involved internal files that, in similar incidents, often contain names, addresses, Social Security numbers, financial details, and payment histories tied to financing agreements.
Microf has not yet issued a public statement detailing the exact scope or the specific categories of customer data involved. Industry trackers monitoring the qilin leak site continue to observe the listing as of the publication date of this article.
Why This Matters for You and Your Family
If you or anyone in your household has ever financed an air conditioner, furnace, water heater, or similar home equipment through Microf, your information could be among the records now in attackers’ hands. Lease-to-own customers with challenged credit are often asked to provide detailed personal and financial data during the quick application process Microf advertises. Once that information leaves the company’s control, it can be used for identity theft, fraudulent loan applications, or sold on underground markets.