Company Details
sofa.com
184
9,412
337
sofa.com
0
SOF_4879021
In-progress

sofa.com Company CyberSecurity Posture
sofa.comWith over 10 years' experience in the industry, we’re experts in our craft, handcrafting every design and offering a lifetime guarantee on all our beautiful solid beechwood frames. Home to over 30 different styles and 100 fabulous fabrics for you to choose from, we’re here to help you create a sofa as unique as you. Handmade to order, enjoy delivery in just 4-6 weeks with a team of experts at every step of your sofa’s journey so that every customer is treated to tip top quality service - there are no middlemen taking a seat on our sofas along the way! From design to delivery, we’ve got your back. We’ve also brought our passion for stylish and sumptuous sofas to all areas of the home – from dreamy beds and snug armchairs, to savvy sofa beds and a decadent dining collection. Come visit us in our stunning showroom locations across the UK (open 7 days a week) and enjoy complimentary fabric samples and a barista-style coffee while you browse, or pop an email or phone call to our friendly customer care team with any queries you may have. We’re a friendly bunch!
Company Details
sofa.com
184
9,412
337
sofa.com
0
SOF_4879021
In-progress
Between 750 and 799

sofa.com Global Score (TPRM)XXXX

Description: The Register has verified that Sports Direct, the biggest sports retail company in the UK, was compromised in the previous year, but the company has yet to notify its employees about the incident. A hacker gained access to the company's internal systems and stole the personal data of its employees, including names, phone numbers, and email and postal addresses. The unpatched version of the DNN platform, which Sports Direct uses to host the staff site, was vulnerable to known vulnerabilities that the attackers took advantage of. As per El Reg, Sports Direct has not yet notified the employees about the data breach. Following its discovery of the hack, the company notified the Information Commissioner's Office of the issue.


No incidents recorded for sofa.com in 2025.
No incidents recorded for sofa.com in 2025.
No incidents recorded for sofa.com in 2025.
sofa.com cyber incidents detection timeline including parent company and subsidiaries

With over 10 years' experience in the industry, we’re experts in our craft, handcrafting every design and offering a lifetime guarantee on all our beautiful solid beechwood frames. Home to over 30 different styles and 100 fabulous fabrics for you to choose from, we’re here to help you create a sofa as unique as you. Handmade to order, enjoy delivery in just 4-6 weeks with a team of experts at every step of your sofa’s journey so that every customer is treated to tip top quality service - there are no middlemen taking a seat on our sofas along the way! From design to delivery, we’ve got your back. We’ve also brought our passion for stylish and sumptuous sofas to all areas of the home – from dreamy beds and snug armchairs, to savvy sofa beds and a decadent dining collection. Come visit us in our stunning showroom locations across the UK (open 7 days a week) and enjoy complimentary fabric samples and a barista-style coffee while you browse, or pop an email or phone call to our friendly customer care team with any queries you may have. We’re a friendly bunch!


Built on a foundation of professional expertise and personal service, Shoppers Drug Mart has been meeting Canadians' health care needs for 50 years. What was once a small pharmacy in Toronto has grown into an organization of over 1,200 stores from coast to coast, becoming an indelible part of the l

Founded in 1930, Publix Super Markets is the largest and fastest-growing employee-owned supermarket chain in the United States. Publix employs over 200,000 associates. We are privately-owned, hold no long-term debt, have avoided layoffs, and continue to grow year after year. Publix and our associate

About UNIQLO LifeWear Apparel that comes from the Japanese values of simplicity, quality, and longevity. Designed to be of the time and for the time, LifeWear is made with such modern elegance that it becomes the building blocks of each individual’s style. A perfect shirt that is always being made m

Menards home improvement stores are conveniently located throughout the Midwest in a 14-state region. From the novice do-it-yourselfer to the experienced contractor, Menards has something for everyone! As a family-owned and operated business, Menards is truly dedicated to service and quality and is

Компания NO ONE более 20 лет занимает лидирующие позиции в розничном сегменте. NO ONE – один из крупнейших дистрибьюторов обуви и аксессуаров ведущих европейских брендов на российском рынке. В портфеле компании NO ONE около 50 европейских марок: Casadei, Fabi, Vicini, Baldinini, Braccialini, Gi
Welcome to Zalando. Here’s some key info about us: Our position and vision: - We’re Europe’s leading online platform for fashion and lifestyle. - Founded in Berlin in 2008, we bring head-to-toe fashion to more than 50 million active customers in 25 markets; offering clothes, footwear, accessories,
.png)
With many years of experience in the supply chain and a degree in Law, Ekaterina Serban came up with the ideal set of tools for her current role...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of sofa.com is http://www.sofa.com.
According to Rankiteo, sofa.com’s AI-generated cybersecurity score is 755, reflecting their Fair security posture.
According to Rankiteo, sofa.com currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, sofa.com is not certified under SOC 2 Type 1.
According to Rankiteo, sofa.com does not hold a SOC 2 Type 2 certification.
According to Rankiteo, sofa.com is not listed as GDPR compliant.
According to Rankiteo, sofa.com does not currently maintain PCI DSS compliance.
According to Rankiteo, sofa.com is not compliant with HIPAA regulations.
According to Rankiteo,sofa.com is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
sofa.com operates primarily in the Furniture and Home Furnishings Manufacturing industry.
sofa.com employs approximately 184 people worldwide.
sofa.com presently has no subsidiaries across any sectors.
sofa.com’s official LinkedIn profile has approximately 9,412 followers.
sofa.com is classified under the NAICS code 337, which corresponds to Furniture and Related Product Manufacturing.
No, sofa.com does not have a profile on Crunchbase.
Yes, sofa.com maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/sofa.com.
As of November 28, 2025, Rankiteo reports that sofa.com has experienced 1 cybersecurity incidents.
sofa.com has an estimated 2,617 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Title: Sports Direct Data Breach
Description: A hacker gained access to the company's internal systems and stole the personal data of its employees, including names, phone numbers, and email and postal addresses.
Type: Data Breach
Attack Vector: Unpatched DNN platform vulnerabilities
Vulnerability Exploited: Known vulnerabilities in DNN platform
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Names, Phone numbers, Email addresses, Postal addresses
Systems Affected: Staff site hosted on DNN platform
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Phone Numbers, Email Addresses, Postal Addresses and .

Entity Name: Sports Direct
Entity Type: Organization
Industry: Retail
Location: UK

Type of Data Compromised: Names, Phone numbers, Email addresses, Postal addresses
Personally Identifiable Information: Yes

Regulatory Notifications: Information Commissioner's Office

Source: The Register
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: The Register.

Root Causes: Unpatched DNN platform
Most Significant Data Compromised: The most significant data compromised in an incident were names, phone numbers, email addresses, postal addresses and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were names, email addresses, postal addresses and phone numbers.
Most Recent Source: The most recent source of information about an incident is The Register.
.png)
ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if the malicious images are embedded in an `iframe` element, during a widget creation, deployed to any page of the platform (e.g., dashboards), and accessed during normal operations. The vulnerability resides in the `ImageController`, which fails to restrict the execution of JavaScript code when an image is loaded by the user's browser. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions.
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint
Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.
Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.