CSIDB logo
Incident

Bassett Furniture Industries

Incident posture

Attack window
Jul 2021
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-23 00:00

Linked entities

Victim
Bassett Furniture Industries
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Bassett Furniture Industries experienced a data breach involving unauthorized code added to its e-commerce website, compromising customer names combined with financial account or payment card details including security codes, access credentials, or PINs. The incident impacted over 7,600 individuals, including a small number of residents from a specific state. Affected customers received written notifications and were offered complimentary credit monitoring and identity restoration services for one year through a third-party provider. The breach spanned an extended period before being discovered and addressed by the company.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Bassett Furniture Industries, Incorporated, a Virginia-based commercial entity, experienced a data breach involving unauthorized access to its e-commerce systems. The breach occurred over an extended period, from July 29, 2021, to April 27, 2023, though the company did not discover the incident until August 23, 2023. Attackers compromised the website by inserting malicious code designed to capture sensitive customer information during online transactions. The acquired data included names combined with financial account details such as credit or debit card numbers, along with associated security codes, access codes, passwords, or PINs. This exposure impacted 7,614 individuals nationwide, including 13 residents of Maine. The prolonged duration of undetected access allowed the malicious code to operate for nearly two years before discovery, significantly expanding the potential window for data exploitation.

Bassett Furniture initiated written notifications to affected consumers on September 22, 2023, approximately one month after discovering the breach. The company offered impacted individuals twelve months of complimentary credit monitoring and identity restoration services through IDX, a third-party provider specializing in data breach response. No prior breach notifications had been issued by the entity within the preceding twelve months. The incident was reported to the Maine Attorney General’s office by J. Michael Daniel, Senior Vice President and Chief Financial and Administrative Officer of Bassett Furniture, confirming organizational awareness of the event’s scope and regulatory obligations. The breach notification did not disclose technical details regarding containment measures or forensic investigations beyond confirming the compromise stemmed from website code manipulation.

Sources

Sources available to members: 1 source.

CSIDB