All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Framework notifies customers of data breach following Metabase hack

Created at 7 Aug · 4:16 PM1 source↑ Market-relevant
IN SHORT

Computer maker Framework has notified all of its customers about a data breach that exposed names, email addresses, phone numbers, and physical addresses. The breach occurred due to a cyberattack on Metabase, a business intelligence company providing services to Framework.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Who's Involved

Framework
Computer maker notifying customers of data breach
Metabase
Business intelligence company experiencing upstream cyberattack
Eric Schumacher
Framework spokesperson
Framework notifies customers of data breach following Metabase hack

↳ Why This Matters

The breach highlights the significant risk posed by supply chain cyberattacks, where a vulnerability in a third-party vendor can expose the data of numerous downstream customers.

Key facts

  • Framework notified all customers of a data breach.
  • Stolen data includes names, email, phone, and physical addresses.
  • The breach resulted from a cyberattack on Metabase, a business intelligence provider.
  • Metabase was hacked via an unknown zero-day security flaw.
  • Hackers accessed Framework's cloud instance through Metabase.
  • Payment information was not compromised.

Computer maker Framework has informed all of its customers about a data breach that resulted in the theft of their personal information. The breach occurred due to a cyberattack on Metabase, a business intelligence company that provides services to Framework. Customers began reporting receiving notification emails on Thursday.

Framework spokesperson Eric Schumacher confirmed that the breach impacted all customers, though a specific number was not disclosed. While Framework computers are considered niche, estimates suggest the company has sold hundreds of thousands of devices. The company attributed the incident to an upstream cyberattack at Metabase.

Metabase, in a blog post, stated that it was compromised by an attacker exploiting an unknown security flaw, a zero-day vulnerability. This exploit allowed hackers to access customer databases stored on Metabase's cloud servers. Framework's notification to its customers included an email from Metabase indicating that hackers had accessed Framework's cloud instance. Following an investigation, Framework confirmed that personal data, including names, email addresses, phone numbers, and physical addresses, had been stolen, but crucially, no payment information was compromised.

Frequently asked questions

Hackers stole customers' names, email addresses, phone numbers, and physical addresses.

No, Framework confirmed that payment information was not included in the stolen data.

The breach occurred due to a cyberattack on Metabase, a third-party business intelligence provider used by Framework, which exploited a zero-day vulnerability.

Metabase, a business intelligence company, was the target of the initial cyberattack.

What Happens Next

01Framework customers will monitor for any misuse of their stolen personal data.
02Metabase may provide further details on the zero-day vulnerability and its remediation.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

Framework notified customers of a data breach.
Customers reported receiving breach notification emails.
Framework confirmed the breach affected all customers.
The breach was attributed to a cyberattack on Metabase.
Metabase disclosed a breach exploiting a zero-day vulnerability.
Hackers accessed Framework's cloud instance via Metabase.
Personal data was stolen, but payment information was not.
Framework investigated and confirmed the data theft.

Sources

T1
Computer maker Framework notifies ‘all customers’ of a data breachTechCrunch

Related Stories

China's Zbtlink suspends router sales over backdoor vulnerability
6 Aug · 6:23 PM
US Companies Face Rising Tide of AI-Driven Cyberattacks
7 Aug · 11:54 AM
Explainer: Who is liable when AI goes rogue? Lawyers see new risks
7 Aug · 10:09 AM
Google: Hackers use phone calls to extort financial firms
6 Aug · 7:51 PM
China's Kimi K3 AI model bypassed UK security test sandbox
7 Aug · 8:39 AM