Company Details
bassett-furniture-industries
1,344
29,167
337
bassettfurniture.com
0
BAS_5925497
In-progress

Bassett Furniture Industries, Inc. Company CyberSecurity Posture
bassettfurniture.comBassett Furniture Industries, Inc. is a leading manufacturer and marketer of high quality, mid to high end priced home furnishings. With more than 90 company and licensee-owned stores, Bassett has leveraged its strong brand name in furniture into a network of corporate and licensed stores that focus on providing consumers with a friendly environment for buying furniture and accessories. Bassett offers custom-built furniture, offering a modern twist on traditional style for home. The stores also feature the latest on-trend furniture styles, a vast selection of upholstery fabrics, free in-home design visits, virtual appointments, and coordinated decorating accessories.
Company Details
bassett-furniture-industries
1,344
29,167
337
bassettfurniture.com
0
BAS_5925497
In-progress
Between 700 and 749

BFII Global Score (TPRM)XXXX

Description: The California Office of the Attorney General reported a data breach regarding Bassett Furniture Industries, Incorporated on September 22, 2023. The breach occurred between July 29, 2021, and April 27, 2023, involving unauthorized access to the e-commerce website, potentially impacting customer names, billing addresses, and payment card information.
Description: On September 22, 2023, the Maine Office of the Attorney General disclosed a prolonged data breach affecting **Bassett Furniture Industries, Incorporated**, spanning from **July 29, 2021, to April 27, 2023**. The incident compromised sensitive financial data of **7,614 individuals**, including **13 Maine residents**. Exposed information included **names, billing addresses, payment card numbers, CVV codes, and expiration dates**—critical details that could facilitate fraudulent transactions or identity theft. The breach’s extended timeline (nearly **22 months**) suggests a sophisticated or undetected intrusion, potentially involving unauthorized access to payment processing systems or databases. While the exact attack vector (e.g., phishing, malware, or third-party vulnerability) was not specified, the exposure of **full payment card details (including CVV codes)** indicates a high-risk scenario for financial fraud. Customers affected may face unauthorized charges, account takeovers, or long-term credit monitoring burdens. The company’s delayed detection and disclosure further amplify reputational and regulatory risks, as prolonged breaches often violate compliance frameworks like **PCI DSS** (Payment Card Industry Data Security Standard). The incident underscores vulnerabilities in data protection practices, particularly for retailers handling high volumes of transactional data.


No incidents recorded for Bassett Furniture Industries, Inc. in 2025.
No incidents recorded for Bassett Furniture Industries, Inc. in 2025.
No incidents recorded for Bassett Furniture Industries, Inc. in 2025.
BFII cyber incidents detection timeline including parent company and subsidiaries

Bassett Furniture Industries, Inc. is a leading manufacturer and marketer of high quality, mid to high end priced home furnishings. With more than 90 company and licensee-owned stores, Bassett has leveraged its strong brand name in furniture into a network of corporate and licensed stores that focus on providing consumers with a friendly environment for buying furniture and accessories. Bassett offers custom-built furniture, offering a modern twist on traditional style for home. The stores also feature the latest on-trend furniture styles, a vast selection of upholstery fabrics, free in-home design visits, virtual appointments, and coordinated decorating accessories.


Patioworld is California's leading retailer of luxury outdoor furniture by the world's top designers - including Brown Jordan, Castelle, Gloster, Kettler, Lane Venture, Les Jardins, and Tropitone. We carry a broad selection of fine outdoor furniture, tents, umbrellas, accessories, home decor, and mo

Our company, Top-Line Furniture Corp. started in 1995 as exclusively designed furniture. iNSPIRE Q is now the name of our home furnishings brand that we have created and market our designs. Our company not only creates over 5,000 home furnishing products but provides How-To’s to help you style your

Collingwood Batchellor began as a home department store in Horley after the acquisition of W.H. Batchellor in 1968. Since then the company has gone on to expand with seven stores across Surrey, Sussex and Kent, becoming one of the leading department store retailers in the South East of the UK with a
Trarem imagine sur mesure… à votre mesure. Trarem est reconnu, depuis 1957, comme le spécialiste de l’aménagement et de l’agencement des environnements de travail et, depuis deux ans, comme une nouvelle référence dans la conception des espaces de vie, sous la marque Trarem Life. Créative et enga

We manufacture casegood furniture for hotels, timeshares, senior living environments and more with materials sourced from the Pacific Northwest. For over 40 years, Northland Furniture has been manufacturing high-quality commercial furniture for hotels, timeshares, senior living environments, colleg

LiFE è la prima catena di negozi monomarca specializzati in cucine in espansione su tutto il territorio italiano. Due linee di prodotto, made in Germany, per soddisfare un'ampia fascia di consumatori. Un nuovo sistema distributivo, con al centro la qualità del lavoro, caratterizzato da un nuovo con
.png)
Key Insights Given the large stake in the stock by institutions, Bassett Furniture Industries' stock price might be...
BASSETT, Va., Oct. 16, 2025 (GLOBE NEWSWIRE) -- Bassett Furniture Industries, Inc. (Nasdaq: BSET) announced today that its Board of...
Bassett posts a Q3 rebound with rising margins and a modest profit, but a shaky retail unit and high dividend payout raise red flags for...
BASSETT, Va., Sept. 30, 2025 (GLOBE NEWSWIRE) -- Bassett Furniture Industries, Inc. (Nasdaq: BSET) today announced it will host a conference...
Bassett Furniture Industries, Inc. (BSET) announced that on July 16, 2025, James E. Goergen was elected a member of its Board of Directors beginning on July 22...
Bassett Furniture agreed to a class action lawsuit settlement to resolve claims a data breach compromised consumer information.
For the latest discoveries in cyber research for the week of 22nd July, please download our Threat Intelligence Bulletin.
Although Bassett Furniture stores and its e-commerce operations are open, the company's ability to fulfill orders has been impacted by the attack.
Basset Furniture, one of the oldest furniture manufacturers in the US, is stopping its manufacturing operations after a ransomware attack on...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Bassett Furniture Industries, Inc. is http://www.bassettfurniture.com.
According to Rankiteo, Bassett Furniture Industries, Inc.’s AI-generated cybersecurity score is 701, reflecting their Moderate security posture.
According to Rankiteo, Bassett Furniture Industries, Inc. currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Bassett Furniture Industries, Inc. is not certified under SOC 2 Type 1.
According to Rankiteo, Bassett Furniture Industries, Inc. does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Bassett Furniture Industries, Inc. is not listed as GDPR compliant.
According to Rankiteo, Bassett Furniture Industries, Inc. does not currently maintain PCI DSS compliance.
According to Rankiteo, Bassett Furniture Industries, Inc. is not compliant with HIPAA regulations.
According to Rankiteo,Bassett Furniture Industries, Inc. is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Bassett Furniture Industries, Inc. operates primarily in the Furniture and Home Furnishings Manufacturing industry.
Bassett Furniture Industries, Inc. employs approximately 1,344 people worldwide.
Bassett Furniture Industries, Inc. presently has no subsidiaries across any sectors.
Bassett Furniture Industries, Inc.’s official LinkedIn profile has approximately 29,167 followers.
Bassett Furniture Industries, Inc. is classified under the NAICS code 337, which corresponds to Furniture and Related Product Manufacturing.
No, Bassett Furniture Industries, Inc. does not have a profile on Crunchbase.
Yes, Bassett Furniture Industries, Inc. maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/bassett-furniture-industries.
As of November 28, 2025, Rankiteo reports that Bassett Furniture Industries, Inc. has experienced 2 cybersecurity incidents.
Bassett Furniture Industries, Inc. has an estimated 2,617 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with public disclosure via maine office of the attorney general..
Title: Bassett Furniture Industries Data Breach
Description: Unauthorized access to the e-commerce website, potentially impacting customer names, billing addresses, and payment card information.
Date Detected: 2023-04-27
Date Publicly Disclosed: 2023-09-22
Type: Data Breach
Attack Vector: Unauthorized Access
Title: Bassett Furniture Industries Data Breach (2021–2023)
Description: The Maine Office of the Attorney General reported a data breach involving Bassett Furniture Industries, Incorporated. The breach occurred between July 29, 2021, and April 27, 2023, affecting 7,614 individuals, including 13 Maine residents. Compromised data included financial account information such as names, billing addresses, payment card numbers, CVV codes, and expiration dates.
Date Publicly Disclosed: 2023-09-22
Type: Data Breach
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Customer names, Billing addresses, Payment card information
Systems Affected: E-commerce Website

Data Compromised: Names, Billing addresses, Payment card numbers, Cvv codes, Expiration dates
Identity Theft Risk: High (financial account information exposed)
Payment Information Risk: High (payment card numbers, CVV codes, expiration dates exposed)
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Customer Names, Billing Addresses, Payment Card Information, , Financial Account Information, Personally Identifiable Information (Pii) and .

Entity Name: Bassett Furniture Industries, Incorporated
Entity Type: Company
Industry: Furniture

Entity Name: Bassett Furniture Industries, Incorporated
Entity Type: Corporation
Industry: Furniture Retail
Location: United States
Customers Affected: 7614

Communication Strategy: Public disclosure via Maine Office of the Attorney General

Type of Data Compromised: Customer names, Billing addresses, Payment card information

Type of Data Compromised: Financial account information, Personally identifiable information (pii)
Number of Records Exposed: 7614
Sensitivity of Data: High
Data Exfiltration: Yes
Personally Identifiable Information: Yes (names, billing addresses)

Regulatory Notifications: Maine Office of the Attorney General

Source: California Office of the Attorney General
Date Accessed: 2023-09-22

Source: Maine Office of the Attorney General
Date Accessed: 2023-09-22
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: California Office of the Attorney GeneralDate Accessed: 2023-09-22, and Source: Maine Office of the Attorney GeneralDate Accessed: 2023-09-22.
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Public disclosure via Maine Office of the Attorney General.
Most Recent Incident Detected: The most recent incident detected was on 2023-04-27.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2023-09-22.
Most Significant Data Compromised: The most significant data compromised in an incident were Customer Names, Billing Addresses, Payment Card Information, , Names, Billing addresses, Payment card numbers, CVV codes, Expiration dates and .
Most Significant System Affected: The most significant system affected in an incident was E-commerce Website.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Names, Billing addresses, Expiration dates, Payment Card Information, CVV codes, Billing Addresses, Customer Names and Payment card numbers.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 765.0.
Most Recent Source: The most recent source of information about an incident are Maine Office of the Attorney General and California Office of the Attorney General.
.png)
ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if the malicious images are embedded in an `iframe` element, during a widget creation, deployed to any page of the platform (e.g., dashboards), and accessed during normal operations. The vulnerability resides in the `ImageController`, which fails to restrict the execution of JavaScript code when an image is loaded by the user's browser. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions.
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint
Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.
Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.