ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

At American Freight we offer high-quality furniture, mattresses and appliances at everyday low prices through our direct-to-consumer, warehouse-style stores and e-commerce site. With more than 5 million satisfied customers, we have built a strong legacy of helping customers save money since 1994. We have over 370 U.S. locations across 40 states, where customers can purchase new and open-box items and “take them home today.” We also provide an array of flexible financing options and extended warranties. To learn more about us and see our great products visit AmericanFreight.com.

American Freight Appliances & Furniture A.I CyberSecurity Scoring

AFAF

Company Details

Linkedin ID:

american-freight-furniture-and-mattress

Employees number:

1,601

Number of followers:

9,212

NAICS:

337

Industry Type:

Furniture and Home Furnishings Manufacturing

Homepage:

americanfreight.com

IP Addresses:

0

Company ID:

AME_1140964

Scan Status:

In-progress

AI scoreAFAF Risk Score (AI oriented)

Between 750 and 799

https://images.rankiteo.com/companyimages/american-freight-furniture-and-mattress.jpeg
AFAF Furniture and Home Furnishings Manufacturing
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreAFAF Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/american-freight-furniture-and-mattress.jpeg
AFAF Furniture and Home Furnishings Manufacturing
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

AFAF Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
American Freight, LLCBreach60311/2020
Rankiteo Explanation :
Attack with significant impact with internal employee data leaks

Description: The Maine Office of the Attorney General reported on August 24, 2021, that American Freight experienced a data breach due to unauthorized access to employees’ email accounts between November 24, 2020, and December 9, 2020. This breach potentially affected 36,829 individuals and specifically compromised the personal information of 59 Maine residents, including names, Social Security numbers, financial account numbers, and payment card numbers. American Freight has offered a complimentary one-year membership in credit monitoring and identity protection services through Kroll.

American Freight, LLC
Breach
Severity: 60
Impact: 3
Seen: 11/2020
Blog:
Rankiteo Explanation
Attack with significant impact with internal employee data leaks

Description: The Maine Office of the Attorney General reported on August 24, 2021, that American Freight experienced a data breach due to unauthorized access to employees’ email accounts between November 24, 2020, and December 9, 2020. This breach potentially affected 36,829 individuals and specifically compromised the personal information of 59 Maine residents, including names, Social Security numbers, financial account numbers, and payment card numbers. American Freight has offered a complimentary one-year membership in credit monitoring and identity protection services through Kroll.

Ailogo

AFAF Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for AFAF

Incidents vs Furniture and Home Furnishings Manufacturing Industry Average (This Year)

No incidents recorded for American Freight Appliances & Furniture in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for American Freight Appliances & Furniture in 2025.

Incident Types AFAF vs Furniture and Home Furnishings Manufacturing Industry Avg (This Year)

No incidents recorded for American Freight Appliances & Furniture in 2025.

Incident History — AFAF (X = Date, Y = Severity)

AFAF cyber incidents detection timeline including parent company and subsidiaries

AFAF Company Subsidiaries

SubsidiaryImage

At American Freight we offer high-quality furniture, mattresses and appliances at everyday low prices through our direct-to-consumer, warehouse-style stores and e-commerce site. With more than 5 million satisfied customers, we have built a strong legacy of helping customers save money since 1994. We have over 370 U.S. locations across 40 states, where customers can purchase new and open-box items and “take them home today.” We also provide an array of flexible financing options and extended warranties. To learn more about us and see our great products visit AmericanFreight.com.

Loading...
similarCompanies

AFAF Similar Companies

Nugget is a kids furniture company with a mission of making furniture for growing imaginations. For us, furniture isn’t just something to sit on — it can be a source of creativity, exploration, and fun. Our first product, The Nugget, blends elements of toy and furniture, opening new worlds of indoo

Nevers Industries Inc

Over our 40-year history, Nevers has established an impressive legacy of beautifully crafted commercial furniture for some of the country’s most prestigious offices. From the Pentagon and Camp David to America’s Fortune 100 and 500 companies, our fit-for-performance solutions fuel workplace producti

Shadow Mountain

Founded as a result of our desire to provide access to high quality, unique home products with the extensive use of specialty materials from around the world. Shadow Mountain is a full line of imported and USA made products of unique Bedroom, Dining Room, Occasional, Upholstery, Area Rugs, Accent

Patioworld

Patioworld is California's leading retailer of luxury outdoor furniture by the world's top designers - including Brown Jordan, Castelle, Gloster, Kettler, Lane Venture, Les Jardins, and Tropitone. We carry a broad selection of fine outdoor furniture, tents, umbrellas, accessories, home decor, and mo

MDF Italia

MDF Italia is a Milan-based design company. Founded by Bruno Fattorini in 1992 and now run by the Cassina family, we create and produce designer items and furnishings characterised by design challenge and essentiality of form. MDF Italia products live in the most diverse contexts, thanks to a univ

For 50 years, Falcon Products has been the go to resource for designers, architects and facility managers interested in high-quality table and seating products. Part of CFGroup’s portfolio of commercial furniture brands, Falcon Products serves a wide variety of clients, including those in the corp

newsone

AFAF CyberSecurity News

February 18, 2025 08:00 AM
American Freight laying off 19 top execs as it closes its business

Appliance and furniture chain American Freight said it will lay off 19 executives from its corporate headquarters in Delaware, Ohio, by May 1.

January 01, 2025 08:00 AM
Popular retail chains closed dozens of Sacramento-area stores in 2024. Here’s who and where

From Big Lots to CVS and Walgreens, these major retailers shut down locations across the capital region.

December 24, 2024 08:00 AM
Furniture & Appliance Chain Liquidating Inventory at 60-80% Off

The parent company of this well-known furniture and appliance chain with 15 Michigan stores is selling off its inventory at 60 to 80 percent off.

December 21, 2024 02:23 AM
American Freight set to open retail store in Albany

American Freight, a national home retail store known for its everyday low prices on quality home furnishings, will open a location at 2304 North Slappey Blvd....

December 11, 2024 08:00 AM
American Freight closes doors nationwide, Ohio HQ hit with massive layoffs

American Freight Group, LLC, headquartered at 109 Innovation Court, has announced a mass layoff of 62 employees, effective February 3, 2025, due to poor...

November 26, 2024 08:00 AM
American Freight closing

American Freight closing. Published: Nov. 26, 2024 at 2:36 PM PST. The API failed to deliver the resource.

November 25, 2024 08:00 AM
Peoria furniture and appliance store is closing amid bankruptcy. Here's what we know

American Freight at 5212 N. Big Hollow Road in Peoria is going out of business. Large, yellow banners hang outside of American Freight at 5212 N. Big Hollow...

November 25, 2024 08:00 AM
American Freight closing 30 Texas locations, including far Northwest Austin store

The discount retailer has mattresses, sofas and kitchen appliances marked up to 40% off.

November 20, 2024 08:00 AM
One Furniture Store to Close All Locations, Including Oklahoma

American Freight Appliances & Furniture is getting the axe - or rather, all American Freight locations across America are closing their doors.

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

AFAF CyberSecurity History Information

Official Website of American Freight Appliances & Furniture

The official website of American Freight Appliances & Furniture is https://www.americanfreight.com.

American Freight Appliances & Furniture’s AI-Generated Cybersecurity Score

According to Rankiteo, American Freight Appliances & Furniture’s AI-generated cybersecurity score is 761, reflecting their Fair security posture.

How many security badges does American Freight Appliances & Furniture’ have ?

According to Rankiteo, American Freight Appliances & Furniture currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does American Freight Appliances & Furniture have SOC 2 Type 1 certification ?

According to Rankiteo, American Freight Appliances & Furniture is not certified under SOC 2 Type 1.

Does American Freight Appliances & Furniture have SOC 2 Type 2 certification ?

According to Rankiteo, American Freight Appliances & Furniture does not hold a SOC 2 Type 2 certification.

Does American Freight Appliances & Furniture comply with GDPR ?

According to Rankiteo, American Freight Appliances & Furniture is not listed as GDPR compliant.

Does American Freight Appliances & Furniture have PCI DSS certification ?

According to Rankiteo, American Freight Appliances & Furniture does not currently maintain PCI DSS compliance.

Does American Freight Appliances & Furniture comply with HIPAA ?

According to Rankiteo, American Freight Appliances & Furniture is not compliant with HIPAA regulations.

Does American Freight Appliances & Furniture have ISO 27001 certification ?

According to Rankiteo,American Freight Appliances & Furniture is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of American Freight Appliances & Furniture

American Freight Appliances & Furniture operates primarily in the Furniture and Home Furnishings Manufacturing industry.

Number of Employees at American Freight Appliances & Furniture

American Freight Appliances & Furniture employs approximately 1,601 people worldwide.

Subsidiaries Owned by American Freight Appliances & Furniture

American Freight Appliances & Furniture presently has no subsidiaries across any sectors.

American Freight Appliances & Furniture’s LinkedIn Followers

American Freight Appliances & Furniture’s official LinkedIn profile has approximately 9,212 followers.

NAICS Classification of American Freight Appliances & Furniture

American Freight Appliances & Furniture is classified under the NAICS code 337, which corresponds to Furniture and Related Product Manufacturing.

American Freight Appliances & Furniture’s Presence on Crunchbase

No, American Freight Appliances & Furniture does not have a profile on Crunchbase.

American Freight Appliances & Furniture’s Presence on LinkedIn

Yes, American Freight Appliances & Furniture maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/american-freight-furniture-and-mattress.

Cybersecurity Incidents Involving American Freight Appliances & Furniture

As of November 28, 2025, Rankiteo reports that American Freight Appliances & Furniture has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

American Freight Appliances & Furniture has an estimated 2,617 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at American Freight Appliances & Furniture ?

Incident Types: The types of cybersecurity incidents that have occurred include Breach.

How does American Freight Appliances & Furniture detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an third party assistance with kroll..

Incident Details

Can you provide details on each incident ?

Incident : Data Breach

Title: American Freight Data Breach

Description: Unauthorized access to employees’ email accounts between November 24, 2020, and December 9, 2020, potentially affecting 36,829 individuals and compromising the personal information of 59 Maine residents.

Date Detected: 2021-08-24

Date Publicly Disclosed: 2021-08-24

Type: Data Breach

Attack Vector: Email Account Compromise

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Breach.

Impact of the Incidents

What was the impact of each incident ?

Incident : Data Breach AME652072625

Data Compromised: Names, Social security numbers, Financial account numbers, Payment card numbers

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Social Security Numbers, Financial Account Numbers, Payment Card Numbers and .

Which entities were affected by each incident ?

Incident : Data Breach AME652072625

Entity Name: American Freight

Entity Type: Company

Industry: Retail

Customers Affected: 36829

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Data Breach AME652072625

Third Party Assistance: Kroll.

How does the company involve third-party assistance in incident response ?

Third-Party Assistance: The company involves third-party assistance in incident response through Kroll, .

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Breach AME652072625

Type of Data Compromised: Names, Social security numbers, Financial account numbers, Payment card numbers

Number of Records Exposed: 36829

Sensitivity of Data: High

Personally Identifiable Information: NamesSocial Security numbers

References

Where can I find more information about each incident ?

Incident : Data Breach AME652072625

Source: Maine Office of the Attorney General

Date Accessed: 2021-08-24

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Maine Office of the Attorney GeneralDate Accessed: 2021-08-24.

Post-Incident Analysis

What is the company's process for conducting post-incident analysis ?

Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Kroll, .

Additional Questions

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on 2021-08-24.

What was the most recent incident publicly disclosed ?

Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2021-08-24.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were Names, Social Security numbers, Financial account numbers, Payment card numbers and .

Response to the Incidents

What third-party assistance was involved in the most recent incident ?

Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was kroll, .

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Payment card numbers, Names, Financial account numbers and Social Security numbers.

What was the number of records exposed in the most significant breach ?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 397.0.

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident is Maine Office of the Attorney General.

cve

Latest Global CVEs (Not Company-Specific)

Description

ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if the malicious images are embedded in an `iframe` element, during a widget creation, deployed to any page of the platform (e.g., dashboards), and accessed during normal operations. The vulnerability resides in the `ImageController`, which fails to restrict the execution of JavaScript code when an image is loaded by the user's browser. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions.

Risk Information
cvss4
Base: 6.2
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).

Risk Information
cvss3
Base: 9.9
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint

Risk Information
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Description

Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.

Description

Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=american-freight-furniture-and-mattress' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge