ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Bassett Furniture Industries, Inc. is a leading manufacturer and marketer of high quality, mid to high end priced home furnishings. With more than 90 company and licensee-owned stores, Bassett has leveraged its strong brand name in furniture into a network of corporate and licensed stores that focus on providing consumers with a friendly environment for buying furniture and accessories. Bassett offers custom-built furniture, offering a modern twist on traditional style for home. The stores also feature the latest on-trend furniture styles, a vast selection of upholstery fabrics, free in-home design visits, virtual appointments, and coordinated decorating accessories.

Bassett Furniture Industries, Inc. A.I CyberSecurity Scoring

BFII

Company Details

Linkedin ID:

bassett-furniture-industries

Employees number:

1,344

Number of followers:

29,167

NAICS:

337

Industry Type:

Furniture and Home Furnishings Manufacturing

Homepage:

bassettfurniture.com

IP Addresses:

0

Company ID:

BAS_5925497

Scan Status:

In-progress

AI scoreBFII Risk Score (AI oriented)

Between 700 and 749

https://images.rankiteo.com/companyimages/bassett-furniture-industries.jpeg
BFII Furniture and Home Furnishings Manufacturing
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreBFII Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/bassett-furniture-industries.jpeg
BFII Furniture and Home Furnishings Manufacturing
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

BFII Company CyberSecurity News & History

Past Incidents
2
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
Bassett Furniture Industries, IncorporatedBreach8547/2021
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: The California Office of the Attorney General reported a data breach regarding Bassett Furniture Industries, Incorporated on September 22, 2023. The breach occurred between July 29, 2021, and April 27, 2023, involving unauthorized access to the e-commerce website, potentially impacting customer names, billing addresses, and payment card information.

Bassett Furniture Industries, IncorporatedBreach8547/2021
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: On September 22, 2023, the Maine Office of the Attorney General disclosed a prolonged data breach affecting **Bassett Furniture Industries, Incorporated**, spanning from **July 29, 2021, to April 27, 2023**. The incident compromised sensitive financial data of **7,614 individuals**, including **13 Maine residents**. Exposed information included **names, billing addresses, payment card numbers, CVV codes, and expiration dates**—critical details that could facilitate fraudulent transactions or identity theft. The breach’s extended timeline (nearly **22 months**) suggests a sophisticated or undetected intrusion, potentially involving unauthorized access to payment processing systems or databases. While the exact attack vector (e.g., phishing, malware, or third-party vulnerability) was not specified, the exposure of **full payment card details (including CVV codes)** indicates a high-risk scenario for financial fraud. Customers affected may face unauthorized charges, account takeovers, or long-term credit monitoring burdens. The company’s delayed detection and disclosure further amplify reputational and regulatory risks, as prolonged breaches often violate compliance frameworks like **PCI DSS** (Payment Card Industry Data Security Standard). The incident underscores vulnerabilities in data protection practices, particularly for retailers handling high volumes of transactional data.

Bassett Furniture Industries, Incorporated
Breach
Severity: 85
Impact: 4
Seen: 7/2021
Blog:
Rankiteo Explanation
Attack with significant impact with customers data leaks

Description: The California Office of the Attorney General reported a data breach regarding Bassett Furniture Industries, Incorporated on September 22, 2023. The breach occurred between July 29, 2021, and April 27, 2023, involving unauthorized access to the e-commerce website, potentially impacting customer names, billing addresses, and payment card information.

Bassett Furniture Industries, Incorporated
Breach
Severity: 85
Impact: 4
Seen: 7/2021
Blog:
Rankiteo Explanation
Attack with significant impact with customers data leaks

Description: On September 22, 2023, the Maine Office of the Attorney General disclosed a prolonged data breach affecting **Bassett Furniture Industries, Incorporated**, spanning from **July 29, 2021, to April 27, 2023**. The incident compromised sensitive financial data of **7,614 individuals**, including **13 Maine residents**. Exposed information included **names, billing addresses, payment card numbers, CVV codes, and expiration dates**—critical details that could facilitate fraudulent transactions or identity theft. The breach’s extended timeline (nearly **22 months**) suggests a sophisticated or undetected intrusion, potentially involving unauthorized access to payment processing systems or databases. While the exact attack vector (e.g., phishing, malware, or third-party vulnerability) was not specified, the exposure of **full payment card details (including CVV codes)** indicates a high-risk scenario for financial fraud. Customers affected may face unauthorized charges, account takeovers, or long-term credit monitoring burdens. The company’s delayed detection and disclosure further amplify reputational and regulatory risks, as prolonged breaches often violate compliance frameworks like **PCI DSS** (Payment Card Industry Data Security Standard). The incident underscores vulnerabilities in data protection practices, particularly for retailers handling high volumes of transactional data.

Ailogo

BFII Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for BFII

Incidents vs Furniture and Home Furnishings Manufacturing Industry Average (This Year)

No incidents recorded for Bassett Furniture Industries, Inc. in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Bassett Furniture Industries, Inc. in 2025.

Incident Types BFII vs Furniture and Home Furnishings Manufacturing Industry Avg (This Year)

No incidents recorded for Bassett Furniture Industries, Inc. in 2025.

Incident History — BFII (X = Date, Y = Severity)

BFII cyber incidents detection timeline including parent company and subsidiaries

BFII Company Subsidiaries

SubsidiaryImage

Bassett Furniture Industries, Inc. is a leading manufacturer and marketer of high quality, mid to high end priced home furnishings. With more than 90 company and licensee-owned stores, Bassett has leveraged its strong brand name in furniture into a network of corporate and licensed stores that focus on providing consumers with a friendly environment for buying furniture and accessories. Bassett offers custom-built furniture, offering a modern twist on traditional style for home. The stores also feature the latest on-trend furniture styles, a vast selection of upholstery fabrics, free in-home design visits, virtual appointments, and coordinated decorating accessories.

Loading...
similarCompanies

BFII Similar Companies

Patioworld

Patioworld is California's leading retailer of luxury outdoor furniture by the world's top designers - including Brown Jordan, Castelle, Gloster, Kettler, Lane Venture, Les Jardins, and Tropitone. We carry a broad selection of fine outdoor furniture, tents, umbrellas, accessories, home decor, and mo

Top-Line Furniture Corp.

Our company, Top-Line Furniture Corp. started in 1995 as exclusively designed furniture. iNSPIRE Q is now the name of our home furnishings brand that we have created and market our designs. Our company not only creates over 5,000 home furnishing products but provides How-To’s to help you style your

Collingwood Batchellor

Collingwood Batchellor began as a home department store in Horley after the acquisition of W.H. Batchellor in 1968. Since then the company has gone on to expand with seven stores across Surrey, Sussex and Kent, becoming one of the leading department store retailers in the South East of the UK with a

TRAREM AFRIQUE

Trarem imagine sur mesure… à votre mesure. Trarem est reconnu, depuis 1957, comme le spécialiste de l’aménagement et de l’agencement des environnements de travail et, depuis deux ans, comme une nouvelle référence dans la conception des espaces de vie, sous la marque Trarem Life. Créative et enga

Northland Furniture

We manufacture casegood furniture for hotels, timeshares, senior living environments and more with materials sourced from the Pacific Northwest. For over 40 years, Northland Furniture has been manufacturing high-quality commercial furniture for hotels, timeshares, senior living environments, colleg

LiFE Cucine

LiFE è la prima catena di negozi monomarca specializzati in cucine in espansione su tutto il territorio italiano. Due linee di prodotto, made in Germany, per soddisfare un'ampia fascia di consumatori. Un nuovo sistema distributivo, con al centro la qualità del lavoro, caratterizzato da un nuovo con

newsone

BFII CyberSecurity News

October 28, 2025 07:00 AM
With 68% institutional ownership, Bassett Furniture Industries, Incorporated (NASDAQ:BSET) is a favorite amongst the big guns

Key Insights Given the large stake in the stock by institutions, Bassett Furniture Industries' stock price might be...

October 16, 2025 07:00 AM
Bassett Announces Regular Quarterly Dividend

BASSETT, Va., Oct. 16, 2025 (GLOBE NEWSWIRE) -- Bassett Furniture Industries, Inc. (Nasdaq: BSET) announced today that its Board of...

October 09, 2025 07:00 AM
Bassett Furniture Stock (BSET): Bounces Back—But Is the Dividend at Risk?

Bassett posts a Q3 rebound with rising margins and a modest profit, but a shaky retail unit and high dividend payout raise red flags for...

September 30, 2025 07:00 AM
Bassett Announces Third Quarter Conference Call

BASSETT, Va., Sept. 30, 2025 (GLOBE NEWSWIRE) -- Bassett Furniture Industries, Inc. (Nasdaq: BSET) today announced it will host a conference...

July 22, 2025 07:00 AM
Bassett Furniture Industries Appoints James Goergen to Board

Bassett Furniture Industries, Inc. (BSET) announced that on July 16, 2025, James E. Goergen was elected a member of its Board of Directors beginning on July 22...

January 31, 2025 08:00 AM
Bassett Furniture data breach class action settlement

Bassett Furniture agreed to a class action lawsuit settlement to resolve claims a data breach compromised consumer information.

July 22, 2024 07:00 AM
22nd July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 22nd July, please download our Threat Intelligence Bulletin.

July 19, 2024 07:00 AM
Bassett Furniture temporarily shuts down manufacturing facilities following cyberattack

Although Bassett Furniture stores and its e-commerce operations are open, the company's ability to fulfill orders has been impacted by the attack.

July 19, 2024 07:00 AM
Shoppers won’t receive furniture orders after ransomware attack

Basset Furniture, one of the oldest furniture manufacturers in the US, is stopping its manufacturing operations after a ransomware attack on...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

BFII CyberSecurity History Information

Official Website of Bassett Furniture Industries, Inc.

The official website of Bassett Furniture Industries, Inc. is http://www.bassettfurniture.com.

Bassett Furniture Industries, Inc.’s AI-Generated Cybersecurity Score

According to Rankiteo, Bassett Furniture Industries, Inc.’s AI-generated cybersecurity score is 701, reflecting their Moderate security posture.

How many security badges does Bassett Furniture Industries, Inc.’ have ?

According to Rankiteo, Bassett Furniture Industries, Inc. currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Bassett Furniture Industries, Inc. have SOC 2 Type 1 certification ?

According to Rankiteo, Bassett Furniture Industries, Inc. is not certified under SOC 2 Type 1.

Does Bassett Furniture Industries, Inc. have SOC 2 Type 2 certification ?

According to Rankiteo, Bassett Furniture Industries, Inc. does not hold a SOC 2 Type 2 certification.

Does Bassett Furniture Industries, Inc. comply with GDPR ?

According to Rankiteo, Bassett Furniture Industries, Inc. is not listed as GDPR compliant.

Does Bassett Furniture Industries, Inc. have PCI DSS certification ?

According to Rankiteo, Bassett Furniture Industries, Inc. does not currently maintain PCI DSS compliance.

Does Bassett Furniture Industries, Inc. comply with HIPAA ?

According to Rankiteo, Bassett Furniture Industries, Inc. is not compliant with HIPAA regulations.

Does Bassett Furniture Industries, Inc. have ISO 27001 certification ?

According to Rankiteo,Bassett Furniture Industries, Inc. is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Bassett Furniture Industries, Inc.

Bassett Furniture Industries, Inc. operates primarily in the Furniture and Home Furnishings Manufacturing industry.

Number of Employees at Bassett Furniture Industries, Inc.

Bassett Furniture Industries, Inc. employs approximately 1,344 people worldwide.

Subsidiaries Owned by Bassett Furniture Industries, Inc.

Bassett Furniture Industries, Inc. presently has no subsidiaries across any sectors.

Bassett Furniture Industries, Inc.’s LinkedIn Followers

Bassett Furniture Industries, Inc.’s official LinkedIn profile has approximately 29,167 followers.

NAICS Classification of Bassett Furniture Industries, Inc.

Bassett Furniture Industries, Inc. is classified under the NAICS code 337, which corresponds to Furniture and Related Product Manufacturing.

Bassett Furniture Industries, Inc.’s Presence on Crunchbase

No, Bassett Furniture Industries, Inc. does not have a profile on Crunchbase.

Bassett Furniture Industries, Inc.’s Presence on LinkedIn

Yes, Bassett Furniture Industries, Inc. maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/bassett-furniture-industries.

Cybersecurity Incidents Involving Bassett Furniture Industries, Inc.

As of November 28, 2025, Rankiteo reports that Bassett Furniture Industries, Inc. has experienced 2 cybersecurity incidents.

Number of Peer and Competitor Companies

Bassett Furniture Industries, Inc. has an estimated 2,617 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Bassett Furniture Industries, Inc. ?

Incident Types: The types of cybersecurity incidents that have occurred include Breach.

How does Bassett Furniture Industries, Inc. detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with public disclosure via maine office of the attorney general..

Incident Details

Can you provide details on each incident ?

Incident : Data Breach

Title: Bassett Furniture Industries Data Breach

Description: Unauthorized access to the e-commerce website, potentially impacting customer names, billing addresses, and payment card information.

Date Detected: 2023-04-27

Date Publicly Disclosed: 2023-09-22

Type: Data Breach

Attack Vector: Unauthorized Access

Incident : Data Breach

Title: Bassett Furniture Industries Data Breach (2021–2023)

Description: The Maine Office of the Attorney General reported a data breach involving Bassett Furniture Industries, Incorporated. The breach occurred between July 29, 2021, and April 27, 2023, affecting 7,614 individuals, including 13 Maine residents. Compromised data included financial account information such as names, billing addresses, payment card numbers, CVV codes, and expiration dates.

Date Publicly Disclosed: 2023-09-22

Type: Data Breach

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Breach.

Impact of the Incidents

What was the impact of each incident ?

Incident : Data Breach BAS005072925

Data Compromised: Customer names, Billing addresses, Payment card information

Systems Affected: E-commerce Website

Incident : Data Breach BAS013091825

Data Compromised: Names, Billing addresses, Payment card numbers, Cvv codes, Expiration dates

Identity Theft Risk: High (financial account information exposed)

Payment Information Risk: High (payment card numbers, CVV codes, expiration dates exposed)

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Customer Names, Billing Addresses, Payment Card Information, , Financial Account Information, Personally Identifiable Information (Pii) and .

Which entities were affected by each incident ?

Incident : Data Breach BAS005072925

Entity Name: Bassett Furniture Industries, Incorporated

Entity Type: Company

Industry: Furniture

Incident : Data Breach BAS013091825

Entity Name: Bassett Furniture Industries, Incorporated

Entity Type: Corporation

Industry: Furniture Retail

Location: United States

Customers Affected: 7614

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Data Breach BAS013091825

Communication Strategy: Public disclosure via Maine Office of the Attorney General

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Breach BAS005072925

Type of Data Compromised: Customer names, Billing addresses, Payment card information

Incident : Data Breach BAS013091825

Type of Data Compromised: Financial account information, Personally identifiable information (pii)

Number of Records Exposed: 7614

Sensitivity of Data: High

Data Exfiltration: Yes

Personally Identifiable Information: Yes (names, billing addresses)

Regulatory Compliance

Were there any regulatory violations and fines imposed for each incident ?

Incident : Data Breach BAS013091825

Regulatory Notifications: Maine Office of the Attorney General

References

Where can I find more information about each incident ?

Incident : Data Breach BAS005072925

Source: California Office of the Attorney General

Date Accessed: 2023-09-22

Incident : Data Breach BAS013091825

Source: Maine Office of the Attorney General

Date Accessed: 2023-09-22

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: California Office of the Attorney GeneralDate Accessed: 2023-09-22, and Source: Maine Office of the Attorney GeneralDate Accessed: 2023-09-22.

Investigation Status

How does the company communicate the status of incident investigations to stakeholders ?

Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Public disclosure via Maine Office of the Attorney General.

Additional Questions

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on 2023-04-27.

What was the most recent incident publicly disclosed ?

Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2023-09-22.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were Customer Names, Billing Addresses, Payment Card Information, , Names, Billing addresses, Payment card numbers, CVV codes, Expiration dates and .

What was the most significant system affected in an incident ?

Most Significant System Affected: The most significant system affected in an incident was E-commerce Website.

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Names, Billing addresses, Expiration dates, Payment Card Information, CVV codes, Billing Addresses, Customer Names and Payment card numbers.

What was the number of records exposed in the most significant breach ?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 765.0.

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident are Maine Office of the Attorney General and California Office of the Attorney General.

cve

Latest Global CVEs (Not Company-Specific)

Description

ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if the malicious images are embedded in an `iframe` element, during a widget creation, deployed to any page of the platform (e.g., dashboards), and accessed during normal operations. The vulnerability resides in the `ImageController`, which fails to restrict the execution of JavaScript code when an image is loaded by the user's browser. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions.

Risk Information
cvss4
Base: 6.2
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).

Risk Information
cvss3
Base: 9.9
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint

Risk Information
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Description

Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.

Description

Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=bassett-furniture-industries' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge