HackingCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_GOVERNMENTMediumContained
Furniture Mart USA
bd_71d6e129a39bb436 · schema v1 · pii pii-v1
Full breach record for Furniture Mart USA →On November 3, 2024, an unknown external actor accessed and copied files from Furniture Mart USA's systems. The breach was discovered on December 26, 2024 after an investigation that began November 3, 2024. Affected data includes names, Social Security numbers, and driver's license or state ID numbers. Approximately 9,718 individuals were affected nationally, including 2 Maine residents. Written notices were sent January 24, 2025; 12 months of free credit monitoring via IDX was offered.
Maine clockDiscovered Dec 26, 2024 → Filed with AG Jan 24, 202529d ✓ ME AG ≤30d29 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_27a4603ba17b9531Vermont State AGfiled 2025-01-24Verified
- bd_4712c04a1d32cb5eIowa State AGfiled 2025-01-24Candidate
- bd_494086341811f39bIndiana State AGfiled 2025-01-24Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/fa4db5b5-edf2-4a1c-98bb-d018ffaefb45.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 24, 2025
- Raw hash
- 8776769ed116391c74a41bbdcb960d2d7e132e454cb39c89f2b35d53b938a32a
Reporting entity
- Name
- Furniture Mart USAnorm: furniture mart usa
- Domain
- fm-usa.com
- Industry
- Other Commercial
Victim entity
- Name
- Furniture Mart USAnorm: furniture mart usa
- Domain
- fm-usa.com
- Industry
- Other Commercial
Incident
- Discovered
- Dec 26, 2024
- Materiality determined
- —
- Notification sent
- Jan 24, 2025
- Affected individuals
- 2
- Data types
- PIIIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified federal law enforcementNotified relevant state regulatorsNotified three major credit reporting agencies (Equifax, Experian, TransUnion)
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 29d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Dec 26, 2024→ Filed with AG: Jan 24, 202529d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.