Framework alerts all users after zero-day breach via Metabase analytics platform
Framework disclosed that a zero-day flaw in Metabase allowed attackers to retrieve personal and business contact details of its entire customer base.
Framework announced that a zero-day vulnerability in the Metabase business-intelligence platform was used to access a wide range of customer information, including personal contact details and, for corporate accounts, company identifiers and billing emails. Metabase detected the intrusion on August 3 and warned Framework on August 6, prompting the laptop maker to change all database credentials and verify that no admin access was altered.
No evidence was found of further system compromise beyond Metabase, and order or payment records were untouched. The company has hired an external forensics team to continue the investigation and is informing regulators, although many jurisdictions do not require reporting for the disclosed data types. This breach occurs amid recent pricing pressures on Framework's hardware components.
Why it matters
Customers' personal and business contact information was exposed, highlighting risks of third-party analytics services.
In this story