Key facts
- Framework notified all customers of a data breach.
- Stolen data includes names, email, phone, and physical addresses.
- The breach resulted from a cyberattack on Metabase, a business intelligence provider.
- Metabase was hacked via an unknown zero-day security flaw.
- Hackers accessed Framework's cloud instance through Metabase.
- Payment information was not compromised.
Computer maker Framework has informed all of its customers about a data breach that resulted in the theft of their personal information. The breach occurred due to a cyberattack on Metabase, a business intelligence company that provides services to Framework. Customers began reporting receiving notification emails on Thursday.
Framework spokesperson Eric Schumacher confirmed that the breach impacted all customers, though a specific number was not disclosed. While Framework computers are considered niche, estimates suggest the company has sold hundreds of thousands of devices. The company attributed the incident to an upstream cyberattack at Metabase.
Metabase, in a blog post, stated that it was compromised by an attacker exploiting an unknown security flaw, a zero-day vulnerability. This exploit allowed hackers to access customer databases stored on Metabase's cloud servers. Framework's notification to its customers included an email from Metabase indicating that hackers had accessed Framework's cloud instance. Following an investigation, Framework confirmed that personal data, including names, email addresses, phone numbers, and physical addresses, had been stolen, but crucially, no payment information was compromised.
