HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Mor Furniture For Less, Inc.
bd_0992816b679fd555 · schema v1 · pii pii-v1
Full breach record for Mor Furniture For Less, Inc. →Mor Furniture for Less, Inc. disclosed a cybersecurity incident occurring between July 13 and 16, 2021, where an unknown third party accessed its network. The breach exposed customer names, addresses, Social Security numbers, and financial account numbers. The company engaged forensic investigators, contained the threat, and offered one year of Experian IdentityWorks credit monitoring to affected individuals.
California clockDiscovered Jul 16, 2021 → Notified Dec 9, 2021146d ✗ CA 60-day late21 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_510120ab1a60612fWashington State AGfiled 2021-12-09Verified
- bd_79de44edb14e1c27Oregon State AGfiled 2021-12-09Verified
- bd_835e3af25cc8eab4Montana State AGfiled 2021-12-09Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-548392
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 9, 2021
- Raw hash
- dd87f9f73de165d47b8fae4aa41b77b5bb4686b7505ccada944f1252bd03faa8
Reporting entity
- Name
- Mor Furniture For Less, Inc.norm: mor furniture for less
Victim entity
- Name
- Mor Furniture For Less, Inc.norm: mor furniture for less
Incident
- Discovered
- Jul 16, 2021
- Materiality determined
- —
- Notification sent
- Dec 9, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 21 weeks(146 days from discovery to filing)
- Compliance flags
- CA 60-day late · 146d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 16, 2021→ Notified: Dec 9, 2021146d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.