Framework Data Breach: Metabase Zero-Day Exposed Every Customer's Details
Framework has told its entire customer base that personal data was stolen in a breach at Metabase, the business intelligence provider the laptop maker uses for analytics. The Framework data breach, disclosed in customer emails sent Thursday, August 6, exposed names, email addresses, phone numbers, physical addresses, and login IPs. Payment and order information was not part of the theft.
Framework built its name on modular, repairable, upgradeable computers, a business model that promises owners lasting control over their hardware. This incident does not involve Framework's own systems: the intrusion happened upstream, at a third-party analytics vendor. The company said it rotated credentials after the incident and confirmed that no unauthorized changes to administrative access occurred outside the Metabase environment.
What the Framework data breach exposed
The accessed database held contact and delivery details for private and commercial customers, according to the notification Framework sent out. For business accounts, the exposure may also cover VAT/EIN numbers and company names.
| Data type | Status |
|---|---|
| Customer names | Accessed |
| Email addresses | Accessed |
| Phone numbers | Accessed |
| Physical addresses | Accessed |
| Login IPs | Accessed |
| VAT/EIN numbers and company names (business accounts) | Accessed |
| Payment card data | Not accessed |
| Order details | Not accessed |
Names, phone numbers, and home addresses are the kind of material fraudsters use to impersonate people or make phishing look credible, and login IPs add a tracking angle. Framework described the incident as a limited breach at a partner. Spokesperson Eric Schumacher confirmed that the event affected the entire customer base but declined to state how many people that covers. The company emailed the full account base rather than a subset of users.
How the Metabase zero-day cascaded
The Framework data breach traces to an unauthenticated SQL injection vulnerability in Metabase versions 1.58 and above, rated 10.0 on the CVSS severity scale, the maximum possible score. The flaw lets remote attackers gain administrator access, modify configurations, and export data from connected databases without logging in. Metabase detected the attack on its cloud service on Monday, August 3; Framework and Tally, another Metabase customer, disclosed the resulting data theft on August 6.
Cloud-hosted Metabase instances were patched automatically, but self-hosted deployments require manual updates to releases such as 0.58.24 or 0.59.21, leaving organizations on older builds exposed until they act. Metabase serves more than 100,000 clients, so other breach disclosures from companies running the same software are plausible. For Framework, the chain is short: customer data was piped into the Metabase instance for business intelligence, the zero-day handed an attacker administrator access, and the connected database was exported in full. The company's storefront and internal systems were not the entry point.
What affected customers should do now
The Framework data breach exposed enough personal detail to fuel targeted phishing, so account hygiene is the immediate priority.
- Change passwords, especially where the same one is reused across services. Exposed emails and login IPs make credential-stuffing attempts more likely.
- Enable two-factor authentication on the Framework account and on any linked email account.
- Watch for password-reset or account-recovery requests you did not initiate.
- Treat unsolicited messages that reference Framework purchases with extra suspicion, since real names and addresses make scams harder to spot.
- Business customers should follow Metabase's guidance for affected organizations: rotate database credentials, review API keys, and inspect logs for POST requests to the password reset endpoint.
Payment details were not accessed, so card fraud is not the immediate concern. The realistic risks are impersonation, credential-reuse attacks, and phishing built on accurate personal information.
Why this matters
Framework sells trust. Its product line exists so users can repair, upgrade, and keep hardware longer, which makes a customer data exposure through a vendor especially hard to square with that promise. The incident shows that a company can secure its own systems and still be undone by a single analytics provider, with a zero-day in widely used software cascading to an entire customer base within days. For Framework owners, the takeaway is practical: unique passwords, two-factor authentication, and skepticism toward unsolicited messages are the defenses that matter most after a breach like this one.
Related Articles
- Meta AI Exploit Leads to Widespread Instagram Account Hijacking via Support Chatbot
- 23andMe Data Breach Settlement: States Win $18 Million Over 6.9 Million Genetic Records Exposed
- Instructure Reaches Settlement to Prevent Massive Canvas LMS Data Leak
✔Human Verified
Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.