
Furniture Giant Lovesac Hit by Malware Attack, Experts Warn of Rising Ransomware Trends
American furniture giant Lovesac has confirmed that it was the victim of a ransomware attack earlier this year, disclosing that malicious actors gained access to parts of its IT infrastructure between February 12 and March 3, 2025. According to the company’s official statement, the breach exposed customer information for nearly 20 days, before Lovesac’s incident response teams successfully contained and blocked the intrusion.
The company revealed that the attack was orchestrated by RansomHub, a well-known ransomware group infamous for its double-extortion tactics. Under this method, attackers not only encrypt a victim’s data to demand ransom but also steal sensitive information, threatening to leak it online if their demands are not met. Lovesac emphasized that it had not entertained ransom negotiations, raising concerns that the attackers might release stolen customer data in retaliation.
To mitigate potential harm, Lovesac has notified all impacted staff, contractors, and customers about the breach. The company is also offering free Experian credit monitoring services, starting from November 2025, to help affected individuals safeguard themselves against identity theft and financial fraud.
Interestingly, after the attack, RansomHub appeared to retreat into obscurity. Security researchers believe this sudden disappearance could be linked to recent global crackdowns on cybercrime syndicates, such as Operation Cronos, which have disrupted several major ransomware operations.
Tenable Confirms Data Breach Linked to Marketing Platforms
Separately, cybersecurity firm Tenable disclosed that it too had suffered a data breach after attackers infiltrated servers linked to its Salesforce and Salesloft Drift Marketing environments. The exposed information included customer names, corporate email addresses, and phone numbers.
Although there is no evidence yet that the stolen data has been weaponized for phishing campaigns or identity fraud, experts caution that such details are highly valuable to cybercriminals. The same server vulnerability is believed to have affected other high-profile companies, including Palo Alto Networks, Zscaler, Google, PagerDuty, and Cloudflare.
Security analysts warn that the breach underscores the ripple effect of supply chain risks—when attackers compromise widely used third-party platforms, multiple organizations become collateral victims.
Australian Study Reveals the “Short Lifespan” of Ransomware Gangs
Meanwhile, a study from the Australian Institute of Criminology has shed new light on the inner workings of ransomware gangs. Contrary to the image of long-running criminal empires, researchers found that most ransomware groups have a surprisingly short operational lifespan of just 1.36 years on average.
During this brief window, gangs aggressively target victims, primarily through phishing campaigns and opportunistic attacks. Their strategy is simple yet effective: strike quickly, extract maximum ransom, and vanish before law enforcement agencies can track them down.
The report also revealed that many of these groups operate with corporate-like structures, complete with specialized roles. Some members handle customer negotiations, others manage technical operations, while still others are tasked with laundering ransom payments, often converting them into cryptocurrency. A few groups even maintain dedicated “support desks” to guide victims through the ransom payment process.
Such professionalization not only maximizes profitability but also helps cybercriminals evade detection. By staying active for only a short span and disbanding before authorities catch up, ransomware gangs minimize exposure while reaping enormous financial rewards.
Conclusion
The incidents at Lovesac and Tenable, combined with the findings from the Australian study, highlight a sobering reality: ransomware attacks are becoming increasingly strategic, organized, and difficult to track. With gangs adopting corporate-style operations and leveraging double-extortion methods, businesses across industries—from furniture retail to cybersecurity—are finding themselves in the crosshairs.
Experts stress that companies must invest not only in robust cybersecurity defenses but also in incident response planning and employee training, as the human factor often remains the weakest link in digital security.
Join our LinkedIn group Information Security Community!








