Framework, a company that manufactures modular and repairable computers, has informed its customer base of a significant data theft incident. Hackers reportedly accessed personal information including names, email addresses, phone numbers, and physical addresses, due to a security lapse at Metabase, the business intelligence service provider.
The breach was discovered when customers began sharing their experiences on social media after receiving notifications from Framework. While Eric Schumacher, spokesperson for Framework, stated that all customers were impacted, he did not provide specific numbers of affected users. Framework computers are niche products, with estimates suggesting around hundreds of thousands have been sold.
In its notification email, Framework attached a message from Metabase, which disclosed the intrusion was due to a previously unknown security flaw. Metabase said hackers exploited this 'zero-day' vulnerability, gaining access to customer data stored on their cloud servers. Framework confirmed that payment details were not compromised during the breach.
The incident highlights the complex nature of cybersecurity in today's interconnected business landscape, with vulnerabilities often arising from third-party services. As for Metabase, they did not respond to inquiries about the situation.







