bytevyte
bytevyte
Language
quick-beats

Framework Data Breach: Metabase Zero-Day Exposed Every Customer's Details

Framework data breach

Framework has told its entire customer base that personal data was stolen in a breach at Metabase, the business intelligence provider the laptop maker uses for analytics. The Framework data breach, disclosed in customer emails sent Thursday, August 6, exposed names, email addresses, phone numbers, physical addresses, and login IPs. Payment and order information was not part of the theft.

Framework built its name on modular, repairable, upgradeable computers, a business model that promises owners lasting control over their hardware. This incident does not involve Framework's own systems: the intrusion happened upstream, at a third-party analytics vendor. The company said it rotated credentials after the incident and confirmed that no unauthorized changes to administrative access occurred outside the Metabase environment.

What the Framework data breach exposed

The accessed database held contact and delivery details for private and commercial customers, according to the notification Framework sent out. For business accounts, the exposure may also cover VAT/EIN numbers and company names.

Data typeStatus
Customer namesAccessed
Email addressesAccessed
Phone numbersAccessed
Physical addressesAccessed
Login IPsAccessed
VAT/EIN numbers and company names (business accounts)Accessed
Payment card dataNot accessed
Order detailsNot accessed

Names, phone numbers, and home addresses are the kind of material fraudsters use to impersonate people or make phishing look credible, and login IPs add a tracking angle. Framework described the incident as a limited breach at a partner. Spokesperson Eric Schumacher confirmed that the event affected the entire customer base but declined to state how many people that covers. The company emailed the full account base rather than a subset of users.

How the Metabase zero-day cascaded

The Framework data breach traces to an unauthenticated SQL injection vulnerability in Metabase versions 1.58 and above, rated 10.0 on the CVSS severity scale, the maximum possible score. The flaw lets remote attackers gain administrator access, modify configurations, and export data from connected databases without logging in. Metabase detected the attack on its cloud service on Monday, August 3; Framework and Tally, another Metabase customer, disclosed the resulting data theft on August 6.

Cloud-hosted Metabase instances were patched automatically, but self-hosted deployments require manual updates to releases such as 0.58.24 or 0.59.21, leaving organizations on older builds exposed until they act. Metabase serves more than 100,000 clients, so other breach disclosures from companies running the same software are plausible. For Framework, the chain is short: customer data was piped into the Metabase instance for business intelligence, the zero-day handed an attacker administrator access, and the connected database was exported in full. The company's storefront and internal systems were not the entry point.

What affected customers should do now

The Framework data breach exposed enough personal detail to fuel targeted phishing, so account hygiene is the immediate priority.

  • Change passwords, especially where the same one is reused across services. Exposed emails and login IPs make credential-stuffing attempts more likely.
  • Enable two-factor authentication on the Framework account and on any linked email account.
  • Watch for password-reset or account-recovery requests you did not initiate.
  • Treat unsolicited messages that reference Framework purchases with extra suspicion, since real names and addresses make scams harder to spot.
  • Business customers should follow Metabase's guidance for affected organizations: rotate database credentials, review API keys, and inspect logs for POST requests to the password reset endpoint.

Payment details were not accessed, so card fraud is not the immediate concern. The realistic risks are impersonation, credential-reuse attacks, and phishing built on accurate personal information.

Why this matters

Framework sells trust. Its product line exists so users can repair, upgrade, and keep hardware longer, which makes a customer data exposure through a vendor especially hard to square with that promise. The incident shows that a company can secure its own systems and still be undone by a single analytics provider, with a zero-day in widely used software cascading to an entire customer base within days. For Framework owners, the takeaway is practical: unique passwords, two-factor authentication, and skepticism toward unsolicited messages are the defenses that matter most after a breach like this one.

✔Human Verified


Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.