← All stories
● Covered by 3 sources · 3 reportsMedium impact2 negative1 neutral

Framework Customer Data Exposed in Metabase Zero-Day Breach

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Framework customer data was exposed due to a Metabase zero-day vulnerability.
  • Exposed data includes names, emails, phone numbers, physical addresses, and login IPs.
  • Payment information was not compromised in the breach.
  • Metabase identified and patched the vulnerability, initiating a forensic investigation.
  • Framework notified all affected customers within six hours of Metabase's alert.

Customer Data Compromised

Framework, a company known for its repairable computers, has informed all its customers about a data breach that exposed personal information. The compromised data includes customer names, email addresses, phone numbers, physical addresses, and login IP addresses. The company confirmed that payment details were not accessed during the incident.

Origin of the Breach

The data exposure originated from an incident at Metabase, a business intelligence provider utilized by Framework. Metabase disclosed that an unknown security flaw, referred to as a zero-day vulnerability, was exploited by hackers. This allowed unauthorized access to customer databases stored on Metabase's cloud servers.

Metabase identified the attack on August 3, and subsequently patched the vulnerability. The company is currently working with a third-party forensic investigation firm to determine the full scope and nature of the event.

Framework's Response

Framework received notification from Metabase regarding the breach and acted quickly, informing its customers within six hours. The company also rotated its credentials following the alert. Framework's spokesperson Eric Schumacher confirmed that the breach affected "all customers" but did not specify an exact number.

Industry Context

This incident highlights the supply chain risks associated with third-party vendors. Companies relying on external services for data management face potential vulnerabilities if those providers experience security breaches. The rapid notification by Framework, following Metabase's discovery and alert, has been noted by some as a transparent and timely response to a security incident.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Framework, a company known for repairable computers, notified customers that their names, login IPs, addresses, phone numbers, and emails were accessed in a data breach of its business database provider, Metabase. This incident highlights the supply chain risks associated with third-party vendors and the importance of robust data security practices for companies relying on external services.

Framework, a modular computer manufacturer, informed all its customers that their names, email addresses, phone numbers, and physical addresses were stolen in a data breach. The incident originated from a zero-day exploit at Metabase, a business intelligence provider used by Framework, which allowed hackers to access Framework's cloud instance.

Framework, a laptop manufacturer, experienced a data breach affecting customer information due to a Metabase 0-day vulnerability. The company notified customers promptly, within six hours of receiving notice from Metabase, though some customers expressed frustration over repeated data exposures from third-party services.