Framework Warns All Customers of Massive Data Breach – Claril Noticias

Modular computer manufacturer Framework has notified all of its customers that their personal details were stolen on Thursday following a zero-day cyberattack on its business intelligence provider, Metabase.

How the Framework Data Leak Unfolded

On Thursday, several Framework customers shared copies of the breach notification email they received on social media platforms.

Framework spokesperson Eric Schumacher confirmed to TechCrunch that the security incident impacted “all customers”. Whilst Schumacher declined to disclose the exact number of affected users, community estimates suggest the niche hardware firm has sold hundreds of thousands of modular devices to date.

The Metabase Zero-Day Exploit

The hardware company pinned the blame for the exposure on an upstream cyberattack targeting Metabase, its business intelligence partner.

In an official blog post, Metabase disclosed its own breach, revealing that malicious actors exploited an unpatched security vulnerability, known as a zero-day flaw. This vulnerability allowed the attackers to gain unauthorised access to customer databases hosted on Metabase’s cloud servers.

What Data Was Compromised?

According to the breach notification, the hackers successfully accessed Framework’s specific cloud instance. A subsequent internal investigation by the computer manufacturer revealed that whilst customer names, email addresses, phone numbers, and physical addresses were exfiltrated, sensitive financial and payment information remained completely unaffected.

Metabase has not yet responded to requests for comment regarding the security failure.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *