A significant Framework data breach has compromised customer information, according to multiple reports and an email from the company shared online. Framework is the firm best known for producing modular, highly repairable and customisable PCs and laptops.
The stolen information includes customer names, email addresses, phone numbers, login IP addresses and physical addresses. In the emails sent to affected customers, the company states that order and payment information was not accessed during the breach.
A Framework spokesperson said that all customers were affected, without specifying an exact number. Estimates suggest the incident impacts hundreds of thousands of customers, even though Framework sells fewer laptops than larger, more established brands.
How the Breach Happened
The breach appears to have been caused by a vulnerability in Metabase Cloud, the open-source analytics software Framework was using. The attacker exploited a zero-day exploit, a previously unknown security flaw in the software, to access a substantial amount of information.
In a blog post, Metabase said the vulnerability has already been patched. However, the company warned that those self-hosting the software may still be vulnerable and should upgrade to the latest point release.
These types of breaches are not uncommon, even for large companies, and they occur across the wider industry. Data breaches are becoming increasingly widespread and severe, while firms often provide less transparency about the scope of compromised information and the methods attackers use to gain access.
What Affected Customers Should Do
If you have been affected by the Framework data breach, there are several measures you can take to minimise the damage. Change any exposed and reused passwords, and enable two-factor authentication if you have not already done so. Keep a close eye on any payment cards linked to the account, and revoke access to services you no longer need.
The incident comes at a challenging time for the company. Framework has been hit hard by the ongoing memory shortage and has raised prices twice this year. The cost increase for memory modules was so significant that the company pared down the RAM loadout on the Framework Laptop 13 Pro, despite the product already being offered for pre-order.
The latest breach may further test consumer confidence as Framework continues to navigate pricing pressures and supply chain challenges. Metabase has confirmed the underlying vulnerability has now been patched.