Company Details
americanfreight
1,546
9,403
337
americanfreight.com
0
AME_2225483
In-progress

American Freight Furniture & Mattress Company CyberSecurity Posture
americanfreight.comAt American Freight we offer high-quality furniture and mattresses at everyday low prices through our direct-to-consumer, warehouse-style stores and e-commerce site. We also provide an array of flexible financing options and extended warranties. To learn more about us and see our great products visit AmericanFreight.com.
Company Details
americanfreight
1,546
9,403
337
americanfreight.com
0
AME_2225483
In-progress
Between 700 and 749

AFFM Global Score (TPRM)XXXX

Description: The Maine Office of the Attorney General reported on August 24, 2021, that American Freight experienced a data breach due to unauthorized access to employees’ email accounts between November 24, 2020, and December 9, 2020. This breach potentially affected 36,829 individuals and specifically compromised the personal information of 59 Maine residents, including names, Social Security numbers, financial account numbers, and payment card numbers. American Freight has offered a complimentary one-year membership in credit monitoring and identity protection services through Kroll.


No incidents recorded for American Freight Furniture & Mattress in 2025.
No incidents recorded for American Freight Furniture & Mattress in 2025.
No incidents recorded for American Freight Furniture & Mattress in 2025.
AFFM cyber incidents detection timeline including parent company and subsidiaries

At American Freight we offer high-quality furniture and mattresses at everyday low prices through our direct-to-consumer, warehouse-style stores and e-commerce site. We also provide an array of flexible financing options and extended warranties. To learn more about us and see our great products visit AmericanFreight.com.

Celestica enables the world's best brands. Through our unrivaled customer-centric approach, we partner with leading companies in aerospace and defense, communications, enterprise, healthtech, industrial, capital equipment, and smart energy to deliver solutions for their most complex challenges. A le

DS Smith provides innovative packaging solutions, paper products and recycling services with a commitment to sustainability and a circular economy. Our core purpose is to Redefine Packaging for a Changing World, and our expert teams work closely with like-minded partners to incorporate renewable re
For the builders and protectors, for the makers and explorers, for those shaping and reshaping our world through hard work and inspiration, Stanley Black & Decker provides the tools and innovative solutions you can trust to get the job done—and we have since 1843. You repair your home and car with

For almost four decades, Patanjali Foods has championed India’s wellness revolution. Founded in 1986, we began with a simple mission: making swadeshi products, affordable and quality-driven for every household. Today, we are a leading FMCG force, offering a wide range of household essentials. From n

Every day, in everything we do, our purpose is to protect, heal and nurture in the relentless pursuit of a cleaner, healthier world. And we have a fight on our hands. A fight to make access to the highest quality hygiene, wellness and nourishment a right and not a privilege. Each of our products is

We empower generations to explore the wonder of childhood and reach their full potential. We treat play as if the future depends on it — because it does. Play is our language, and we speak to our consumers authentically by representing the world as they see and imagine it. Mattel is a leading glob
.png)
The chain has confirmed some shutdowns, but multiple locations have advertised store closing sales with no notice.
American Freight Dothan manager Alan Miles tells us about the process and feelings behind the furniture retailer returning to the area.
With 60 retail locations, American Freight offers a wide selection of items for every room in the home - DUBLIN, Ohio, Nov.
The furniture business, which saw a spike in sales during the Covid pandemic, has largely gone in the other direction.
New owner, brand refresh: American Freight Furniture, Mattress re-opens in Dothan · Michelle Mann · Oct 21, 2025 · Oct 21, 2025 · 0. New owner,...
American Freight owner denies, counterclaims by Franchise Group ... WILMINGTON, Del. — AF Newco, owner of American Freight, filed an answer to and...
In the document, FRG put forth four key allegations against AF Newco. They include threats to data access and deletion; the breach of a May 28,...
Usually, when a big-name retail brand closes all of its locations after a bankruptcy liquidation, that's the end of the company,...
DUBLIN, Ohio, Sept. 15, 2025 (SEND2PRESS NEWSWIRE) -- Despite recent reports, American Freight stores remain open across the United States.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of American Freight Furniture & Mattress is https://www.americanfreight.com.
According to Rankiteo, American Freight Furniture & Mattress’s AI-generated cybersecurity score is 738, reflecting their Moderate security posture.
According to Rankiteo, American Freight Furniture & Mattress currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, American Freight Furniture & Mattress is not certified under SOC 2 Type 1.
According to Rankiteo, American Freight Furniture & Mattress does not hold a SOC 2 Type 2 certification.
According to Rankiteo, American Freight Furniture & Mattress is not listed as GDPR compliant.
According to Rankiteo, American Freight Furniture & Mattress does not currently maintain PCI DSS compliance.
According to Rankiteo, American Freight Furniture & Mattress is not compliant with HIPAA regulations.
According to Rankiteo,American Freight Furniture & Mattress is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
American Freight Furniture & Mattress operates primarily in the Furniture and Home Furnishings Manufacturing industry.
American Freight Furniture & Mattress employs approximately 1,546 people worldwide.
American Freight Furniture & Mattress presently has no subsidiaries across any sectors.
American Freight Furniture & Mattress’s official LinkedIn profile has approximately 9,403 followers.
American Freight Furniture & Mattress is classified under the NAICS code 337, which corresponds to Furniture and Related Product Manufacturing.
No, American Freight Furniture & Mattress does not have a profile on Crunchbase.
Yes, American Freight Furniture & Mattress maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/americanfreight.
As of November 28, 2025, Rankiteo reports that American Freight Furniture & Mattress has experienced 1 cybersecurity incidents.
American Freight Furniture & Mattress has an estimated 2,617 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an third party assistance with kroll..
Title: American Freight Data Breach
Description: Unauthorized access to employees’ email accounts between November 24, 2020, and December 9, 2020, potentially affecting 36,829 individuals and compromising the personal information of 59 Maine residents.
Date Detected: 2021-08-24
Date Publicly Disclosed: 2021-08-24
Type: Data Breach
Attack Vector: Email Account Compromise
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Names, Social security numbers, Financial account numbers, Payment card numbers
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Social Security Numbers, Financial Account Numbers, Payment Card Numbers and .

Entity Name: American Freight
Entity Type: Company
Industry: Retail
Customers Affected: 36829

Third Party Assistance: Kroll.
Third-Party Assistance: The company involves third-party assistance in incident response through Kroll, .

Type of Data Compromised: Names, Social security numbers, Financial account numbers, Payment card numbers
Number of Records Exposed: 36829
Sensitivity of Data: High
Personally Identifiable Information: NamesSocial Security numbers

Source: Maine Office of the Attorney General
Date Accessed: 2021-08-24
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Maine Office of the Attorney GeneralDate Accessed: 2021-08-24.
Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Kroll, .
Most Recent Incident Detected: The most recent incident detected was on 2021-08-24.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2021-08-24.
Most Significant Data Compromised: The most significant data compromised in an incident were Names, Social Security numbers, Financial account numbers, Payment card numbers and .
Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was kroll, .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Payment card numbers, Names, Financial account numbers and Social Security numbers.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 397.0.
Most Recent Source: The most recent source of information about an incident is Maine Office of the Attorney General.
.png)
ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if the malicious images are embedded in an `iframe` element, during a widget creation, deployed to any page of the platform (e.g., dashboards), and accessed during normal operations. The vulnerability resides in the `ImageController`, which fails to restrict the execution of JavaScript code when an image is loaded by the user's browser. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions.
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint
Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.
Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.