Framework notifies all customers of data breach via Metabase hack
Modular computer maker Framework says hackers accessed customer names, emails, phone numbers, and addresses through a zero-day exploit at upstream vendor Metabase.
Conversation activity · last 3 days peak 2/hr
Summary, timeline and people extracted by Claude from 5 items across 5 sources · 21h ago. Quotes are verbatim.
Framework, a computer maker known for modular repairable devices, notified all of its customers on August 7 that a data breach exposed their personal information including names, email addresses, phone numbers, and physical addresses. The breach was caused by a zero-day vulnerability at Metabase, a business intelligence platform that Framework used; hackers exploited this flaw to access Framework's customer database stored on Metabase's cloud servers. Payment information was not compromised.
- Framework disclosed a data breach affecting all customers through an upstream Metabase vulnerability exploited via a zero-day flaw.
- Stolen data includes names, emails, phone numbers, and physical addresses; payment information was not compromised.
- Metabase confirmed its own breach in a separate blog post, acknowledging hackers exploited an unknown zero-day to access customer databases.
- Framework sent notification emails to customers on August 7, with estimates suggesting hundreds of thousands of devices were sold.
How it unfolded
-
Reaction Story reaches Hacker News
The TechCrunch article is shared on Hacker News, continuing discussion of the incident.
-
Reaction Story spreads on social media
News of the breach circulates on Bluesky and other social platforms, with multiple Framework customers confirming receipt of breach notification emails.
-
Report TechCrunch reports Framework breach
TechCrunch publishes article confirming Framework's notification of all customers and identifies Metabase as the source of the upstream attack.
-
Event Framework detects breach, notifies customers
Framework discovers that hackers accessed customer data through a Metabase vulnerability and sends notification emails to all affected customers.
-
Event Metabase discloses own breach
Metabase posts blog announcement of its own breach caused by an unknown zero-day security flaw that allowed hackers to access customer databases on its cloud servers.
What people are saying verbatim
“all customers”
Eric Schumacher, Framework spokesperson · TechCrunch · Aug 6
“hackers stole their names, email addresses, phone numbers, and physical addresses”
TechCrunch, News outlet · TechCrunch · Aug 6
“the company blamed the data breach on an upstream cyberattack at Metabase”
TechCrunch, News outlet · TechCrunch · Aug 6
“hackers had stolen its customers' personal data, but did not include their payment information”
Framework, Computer maker · TechCrunch · Aug 6