Computer Maker Framework Informs All Customers of Data Breach via Metabase Hack
Framework, the manufacturer known for producing modular and repairable computers, has issued notifications to all of its customers regarding a data breach that exposed their personal contact information. The incident stems from an upstream cyberattack targeting Metabase, a business intelligence service used by the computer maker.
What Happened
Customers began reporting on social media on Thursday that they had received data breach notification emails from Framework. The company confirmed that unauthorized actors obtained personal customer data, including full names, email addresses, phone numbers, and physical addresses.
Framework spokesperson Eric Schumacher confirmed to TechCrunch that the security breach impacted “all customers,” though the company declined to release a specific figure regarding the total number of individuals affected. Framework attributed the compromise to an upstream security incident at Metabase.
According to a blog post published on Metabase’s official website, an attacker exploited an unknown security flaw, commonly referred to as a zero-day vulnerability. This exploit allowed the hackers to access customer databases hosted on Metabase’s cloud infrastructure. In the breach notification sent to users, Framework shared communications received from Metabase confirming that hackers had accessed Framework’s specific cloud instance.
Key Highlights
- Affected Information: Stolen records include customer names, email addresses, phone numbers, and physical delivery addresses.
- Financial Data Safe: Framework stated that an investigation into the incident confirmed that payment information was not accessed or stolen.
- Scope: The breach impacts all Framework customers, though exact figures were not disclosed by the company.
- Root Cause: The breach originated from an upstream zero-day vulnerability in the cloud systems of business intelligence provider Metabase.
Why This Matters
The incident highlights the risks associated with third-party and upstream service providers. Even though Framework’s internal hardware operations were not the direct target, the integration of third-party business intelligence tools exposed customer contact databases to unauthorized access. Framework clarified that its investigation found no compromise of financial or payment details.
What to Watch Next
Framework has completed an initial investigation and sent out notices to all affected account holders. Metabase disclosed the zero-day incident on its official blog post but did not respond to requests for further comment.
Frequently Asked Questions
What customer data was compromised in the Framework breach?
The stolen data includes customer names, email addresses, telephone numbers, and physical addresses. Payment information was not compromised.
How did the breach occur?
Hackers exploited an unknown security flaw (zero-day vulnerability) at Metabase, a cloud-based business intelligence provider utilized by Framework, allowing unauthorized access to Framework’s cloud database instance.
How many customers are affected?
A spokesperson for Framework confirmed that all customers are affected by the breach, although the company declined to specify the exact number of individuals impacted.
Source: TechCrunch
