Framework data breach exposes customer details
A zero-day in Metabase exposed Framework customer names, emails, and addresses; payment data was safe.
Framework, the modular laptop maker known for repairability, has warned customers that a zero-day vulnerability in its analytics provider, Metabase, let an attacker access names, email addresses, phone numbers, physical addresses, and login IP addresses. The disclosure comes via an email shared on Reddit, and the company said business customers may also have had company names, VAT or Employer Identification Numbers, and billing email addresses exposed. Framework stressed that order and payment details were not affected.
The incident, which hit all customers according to a statement to TechCrunch, is a stark reminder that even the most hardware-friendly companies can't fully shield personal data when third-party services are compromised.
Zero-day in Metabase's cloud
The breach began with a previously unknown vulnerability in Metabase, the business intelligence platform Framework uses for analytics. Metabase's own blog post confirms that an attacker targeted its cloud service, exploiting a bug affecting versions 1.58 and later. The company has since blocked the endpoints used in the attack, patched the flaw, and deployed the fix across its cloud service.
Framework's account of the incident provides a detailed timeline. Metabase discovered the attack on August 3 and notified Framework at 9am Pacific Time on August 6, telling the laptop maker that its instance had been vulnerable and that the attacker had successfully gained access.
According to Metabase, exploitation of the vulnerability can allow an attacker to inject arbitrary SQL against the application's database and potentially gain administrator access. From there, they could alter configuration settings, steal credentials for databases connected to Metabase, query data those connections can access, and export the results.
Framework's response and investigation
Framework said it rotated credentials for every database connected to its Metabase instance and found no changes to admin access or evidence that systems outside Metabase had been accessed. The company has also brought in a third-party forensics firm to investigate, though it cautioned that its findings so far are preliminary.
In its email, Framework said, "We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors." The company added that it's notifying regulators where required, though it noted that names, email addresses, phone numbers, and physical addresses don't cross the mandatory reporting threshold in many regions. Customers are getting the heads-up regardless.
Patch and post-breach steps
Metabase has advised anyone running their own instance to patch immediately. If the vulnerable password-reset endpoint was exposed to the internet, admins have more work ahead: they should kill active sessions, check for rogue API keys or admin accounts, rotate database credentials, and dig through logs for anything suspicious.
Framework is reviewing how customer information is made available through external analytics services, but hasn't yet said what changes that review might produce.
A difficult year for Framework
The breach lands during an already bumpy spell for Framework and its customers. In July, the repairable PC maker warned that the price it was being charged for LPCAMM2 memory used in its Laptop 13 Pro had more than doubled, forcing it to raise memory prices rather than swallow the increase. It also warned that CPU prices were heading upward and could push overall system prices higher in the coming weeks.
Being able to replace almost every part of your laptop is handy. Finding your home address exposed through an analytics service is rather less so.
Why it matters
This breach underscores the risk of trusting third-party analytics services with sensitive customer data. Even companies that emphasize hardware repairability and user control are vulnerable to supply-chain attacks in the software layer. For Framework, the incident could erode customer trust, especially among those who chose the brand for its transparency and ethical stance. As the investigation continues, Framework's promise to review its data storage methodology will be crucial in reassuring customers that their information is safe.
Sources
- The Register Original source
Continue Reading
Hostile SIMs exploit spec-compliant commands
Malicious SIM cards can force phones to leak files, drop to 2G, or crash—by abusing standard SIM commands.
Gray to White: A Hacker's Redemption Arc
Marcus Hutchins, who halted WannaCry, recounts his path from malware author to security researcher.
Cyber Prep Gap Leaves UK Factories Vulnerable
New Make UK report finds half of UK manufacturers lack a formal cyber incident response plan despite rising incidents.