Textile company Sferra Fine Linens on Friday announced that it has started notifying individuals of a cybersecurity incident involving their personal information.
Founded in 1891, Sferra designs and sells Italian-made luxury linen products, including luxury sheets, table linens, and bedding collections, as well as decorative home accessories.
Sferra has announced that it identified the incident on April 24, but that the threat actor had access to its servers for roughly two weeks prior to that.
Impacted personal information, the company announced, includes names, addresses, birth dates, passport information, driver’s license data, Social Security numbers, financial account information, medical and/or health insurance data, electronic/digital signatures, and account credentials.
Based on the type of compromised data, it appears that it mainly belongs to Sferra employees. However, the company has not shared information on the number of impacted individuals.
“Please note, this event did not impact any of Sferra’s e-commerce platforms or any information retained in our e-commerce systems,” the company says.
It’s unclear if this was an attack conducted by a ransomware gang. SecurityWeek has checked the leak websites of major groups, but has not found any mention of Sferra.
Related: OneTouchPoint Discloses Data Breach Impacting Over 30 Healthcare Firms
Related: Data Breach at PFC USA Impacts Patients of 650 Healthcare Providers
Related: IBM Security: Cost of Data Breach Hitting All-Time Highs
Related: DigitalOcean Discloses Impact From Recent Mailchimp Cyberattack

More from Ionut Arghire
- Critical WooCommerce Payments Vulnerability Leads to Site Takeover
- PoC Exploit Published for Just-Patched Veeam Data Backup Solution Flaw
- CISA Gets Proactive With New Pre-Ransomware Alerts
- CISA, NSA Issue Guidance for IAM Administrators
- Cisco Patches High-Severity Vulnerabilities in IOS Software
- ‘Nexus’ Android Trojan Targets 450 Financial Applications
- ‘Badsecrets’ Open Source Tool Detects Secrets in Many Web Frameworks
- Chrome 111 Update Patches High-Severity Vulnerabilities
Latest News
- CISA Ships ‘Untitled Goose Tool’ to Hunt for Microsoft Azure Cloud Infections
- Critical WooCommerce Payments Vulnerability Leads to Site Takeover
- PoC Exploit Published for Just-Patched Veeam Data Backup Solution Flaw
- CISA Gets Proactive With New Pre-Ransomware Alerts
- Watch on Demand: Supply Chain & Third-Party Risk Summit Sessions
- TikTok CEO Grilled by Skeptical Lawmakers on Safety, Content
- CISA, NSA Issue Guidance for IAM Administrators
- Analysis: SEC Cybersecurity Proposals and Biden’s National Cybersecurity Strategy
