• 2 min read
Framework discloses customer data breach
Framework says a Metabase breach exposed customer contact and address data, but not payment information. A forensic investigation is ongoing.

Image: ITzine
Framework has told all customers that their personal data was exposed in a breach of Metabase, its database provider. The incident did not expose payment information, according to Framework’s notification, as reported by ITzine citing Engadget.
The company sent its disclosure late on Thursday, August 6. The exposed information included:
- Customer names
- Login IP addresses
- Postal addresses
- Phone numbers
- Email addresses
Metabase detected the attack on August 3 and began investigating. In its own blog post, the provider said the attacker gained access through an unknown zero-day vulnerability that has since been identified and fixed. Metabase is continuing to work with an independent forensics firm to determine the full scope of the incident.

Recommended reading
Shield AI tests Hivemind swarm with Taiwan drone boats
Framework’s response to the breach
Framework said it rotated credentials after learning of the intrusion and reviewed access controls. The company said it found no changes to administrative access and no evidence that systems outside Metabase had been accessed or altered.
It is also reviewing and updating how it stores data with external database providers. That response limits the currently reported impact, but the company has not disclosed how many customers were affected, how long the attacker had access, or whether the exposed information has been misused. The independent forensic investigation is still underway.
The breach comes after a difficult stretch for Framework’s customer operations. The company raised prices twice earlier this year, in January and March, and later reduced the memory included in some preorders for the new Framework Laptop Pro. Customers who rejected the revised terms were offered full refunds.
For now, this is a serious privacy incident rather than a reported payment-card breach: contact and address data were exposed, while payment records were not. The unresolved forensic findings—especially the number of affected customers and the duration of access—will determine whether that assessment changes.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via ITzine


