HackingVulnerability ExploitCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
BASSETT FURNITURE INDUSTRIES INC
bd_02fbfffce87a6eeb · schema v1 · pii pii-v1
Full breach record for BASSETT FURNITURE INDUSTRIES INC →Bassett Furniture Industries disclosed that an unauthorized actor gained access to its e-commerce website between July 29, 2021, and April 27, 2023, adding code potentially capable of capturing customer information during online orders. The investigation concluded on August 21, 2023. Potentially affected data includes names, billing addresses, payment card numbers, CVV codes, and expiration dates. The company engaged third-party cybersecurity specialists and is offering 12 months of credit monitoring and identity restoration services.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_67e96fb6743a4784Montana State AGfiled 2023-09-22Verified
- bd_c0f90f75baae0abeVermont State AGfiled 2023-09-22Verified
- bd_e2a4d8b329957e70Maine State AGfiled 2023-09-22Candidate
- bd_f5626a67e85caeebNew Hampshire State AGfiled 2023-09-22Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-574059
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 22, 2023
- Raw hash
- 74b4a3eae4edb3cf1e81422f2fcccdea8794f3a6a5213803321ef610f8def02f
Reporting entity
- Name
- BASSETT FURNITURE INDUSTRIES INCnorm: bassett furniture
- Domain
- bassettfurniture.com
Victim entity
- Name
- BASSETT FURNITURE INDUSTRIES INCnorm: bassett furniture
- Domain
- bassettfurniture.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Sep 22, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.