Modular and repairable computer maker Framework has notified its entire customer base regarding a data breach involving personal information. The incident stems from an upstream cyberattack affecting a third-party business intelligence provider utilized by the hardware manufacturer.
According to notifications sent to users, hackers accessed names, email addresses, phone numbers, and physical addresses of virtually all buyers. The company confirmed, however, that payment card details and financial information were not compromised during the security breach.
The breach originated from a zero-day vulnerability exploited in Metabase cloud servers, exposing connected client databases. The event highlights the growing risks associated with supply chain dependencies and third-party software integrations in modern cybersecurity.
- Framework alerts all customers regarding a third-party data breach
- Stolen data includes names, emails, phone numbers, and addresses
- Breach traced back to a zero-day exploit on the Metabase platform
- Customer payment details and financial records remain safe
Sources:
