Company Details
corsi-group-the
42
469
337
thecorsigroup.com
0
THE_6146777
In-progress

The Corsi Group Company CyberSecurity Posture
thecorsigroup.comThe Corsi Group has been building cabinets since 1973. We operate out of Indianapolis, Indiana, our headquarters, as well as facilities in Elkins, West Virginia. We have authorized sales representatives and dealers across the U.S., serving the custom cabinet market. We manufacture two premium cabinet brands: Greenfield Cabinetry and Siteline Cabinetry. We are active members of both the KCMA (Kitchen Cabinet Manufacturers’ Association) and the NKBA (National Kitchen and Bath Association). Our products are CARB-compliant and meet or exceed national standards for safety and durability.
Company Details
corsi-group-the
42
469
337
thecorsigroup.com
0
THE_6146777
In-progress
Between 700 and 749

CG Global Score (TPRM)XXXX

Description: The Corsi Group suffered a security incident in which an unauthorized party gained access to an employee’s email account between **November 6, 2020, and November 19, 2020**. The breach exposed the personal information of **112 individuals**, including at least one Maine resident whose **name and Social Security number (SSN)** were compromised. While the exact method of access was not detailed, the incident suggests a **phishing or credential-theft attack** targeting the employee’s account. In response, the company offered **identity theft protection services via Kroll** to affected individuals to mitigate potential risks like fraud or misuse of the exposed SSN. The breach highlights vulnerabilities in email security and the risks associated with employee account compromises, particularly when sensitive personally identifiable information (PII) is involved. No evidence was provided regarding broader system infiltration or additional data exfiltration beyond the email account.


No incidents recorded for The Corsi Group in 2025.
No incidents recorded for The Corsi Group in 2025.
No incidents recorded for The Corsi Group in 2025.
CG cyber incidents detection timeline including parent company and subsidiaries

The Corsi Group has been building cabinets since 1973. We operate out of Indianapolis, Indiana, our headquarters, as well as facilities in Elkins, West Virginia. We have authorized sales representatives and dealers across the U.S., serving the custom cabinet market. We manufacture two premium cabinet brands: Greenfield Cabinetry and Siteline Cabinetry. We are active members of both the KCMA (Kitchen Cabinet Manufacturers’ Association) and the NKBA (National Kitchen and Bath Association). Our products are CARB-compliant and meet or exceed national standards for safety and durability.


Our team listens to, and engages with, every customer before developing an office furniture solution. Why? We believe each customer has a singular set of conditions and requirements that make them unique. Our job is to uncover the program attributes and develop exceptional possibilities by carefu

Manufacturers of all kind of office chairs, computer chairs, Revolving chairs, school furniture.Welcome to Chairs Bazaar. We have an extensive catalog of chairs to fit nearly any need. Our equality executive chairs, low back chairs, office chairs, waiting room chairs, revolving chairs and other chai

Our business has been built on trust and reliability, whilst offering the right products for the right environment along with national coverage supported by local service. Our customers don’t just get the best products. They also get a first class service and benefit from our free planning, installa

Devon&Devon, which was established in Florence in 1989 and has been part of the Italcer Group since 2017, is an Italian company known globally as the ambassador of a unique way of experiencing home & living. The company accompanies the design choices of its clients with exclusive, complete and coo

TrackDesign is the first Italian e-commerce dedicated to all lovers of design and realizations in Corten steel for interiors and outdoor living spaces. The online store offers design furniture and modern complements, created by designers selected by TrackDesign. We work with great attention the ste
We're a specialty lifestyle home furnishing retailer selling modern furniture, art and accessories in retail stores in several states in the U.S. We offer a custom upholstery line, real wood goods, colorful accessories, large-scale art and more. Our design consultants are designers first, salespe
.png)
MTN Group said it has suffered a cybersecurity breach that led to unauthorized access to personal information belonging to customers in certain markets.
Introduction to (cyber-)security by experts from the ESA Security Office. Between 8 and 12 April 2024, a group of thirty university students...
Learn how to build your own Security Operations Center or improve an existing one within your organization.
Enhance your team's cybersecurity skills with hands-on training in secure product development, threat detection, management and response.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of The Corsi Group is https://www.thecorsigroup.com/.
According to Rankiteo, The Corsi Group’s AI-generated cybersecurity score is 734, reflecting their Moderate security posture.
According to Rankiteo, The Corsi Group currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, The Corsi Group is not certified under SOC 2 Type 1.
According to Rankiteo, The Corsi Group does not hold a SOC 2 Type 2 certification.
According to Rankiteo, The Corsi Group is not listed as GDPR compliant.
According to Rankiteo, The Corsi Group does not currently maintain PCI DSS compliance.
According to Rankiteo, The Corsi Group is not compliant with HIPAA regulations.
According to Rankiteo,The Corsi Group is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
The Corsi Group operates primarily in the Furniture and Home Furnishings Manufacturing industry.
The Corsi Group employs approximately 42 people worldwide.
The Corsi Group presently has no subsidiaries across any sectors.
The Corsi Group’s official LinkedIn profile has approximately 469 followers.
The Corsi Group is classified under the NAICS code 337, which corresponds to Furniture and Related Product Manufacturing.
No, The Corsi Group does not have a profile on Crunchbase.
Yes, The Corsi Group maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/corsi-group-the.
As of November 28, 2025, Rankiteo reports that The Corsi Group has experienced 1 cybersecurity incidents.
The Corsi Group has an estimated 2,617 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an third party assistance with kroll (identity theft protection services)..
Common Attack Types: The most common types of attacks the company has faced is Breach.
Identification of Attack Vectors: The company identifies the attack vectors used in incidents through Employee Email Account.
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personal Identifiable Information (Pii) and .
Third-Party Assistance: The company involves third-party assistance in incident response through Kroll (Identity Theft Protection Services), .
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Maine Office of the Attorney GeneralDate Accessed: 2021-01-20.
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: was Identity theft protection services offered to affected individuals via Kroll.
Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Kroll (Identity Theft Protection Services), .
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2021-01-20.
Most Significant Data Compromised: The most significant data compromised in an incident were Name, Social Security Number and .
Most Significant System Affected: The most significant system affected in an incident was Employee Email Account.
Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was kroll (identity theft protection services), .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Name and Social Security Number.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 112.0.
Most Recent Source: The most recent source of information about an incident is Maine Office of the Attorney General.
Most Recent Customer Advisory: The most recent customer advisory issued was an Identity theft protection services offered to affected individuals via Kroll.
Most Recent Entry Point: The most recent entry point used by an initial access broker was an Employee Email Account.
.png)
ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if the malicious images are embedded in an `iframe` element, during a widget creation, deployed to any page of the platform (e.g., dashboards), and accessed during normal operations. The vulnerability resides in the `ImageController`, which fails to restrict the execution of JavaScript code when an image is loaded by the user's browser. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions.
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint
Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.
Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.