Framework breach exposes customer PII via Metabase zero-day; no payment data hit
Framework has notified customers of a data breach stemming from a zero-day vulnerability in Metabase, the third-party business-intelligence platform it used to analyze customer data. Names, email addresses, and physical addresses were among the exposed fields, but payment information was not affected because Framework routes transactions through Stripe. Notably, the leak also reached people who never purchased hardware and had only joined a waitlist, indicating the analytics dataset was broad. Framework says it is now scoping down the data shared with BI tools to only the columns needed for analysis — an admission that the prior exposure was likely excessive.
The disclosure timeline drew praise: Metabase reportedly notified partners within three days of discovering the incident, and Framework confirmed and alerted customers roughly six hours after being informed. Community sentiment is a mix of appreciation for that speed and transparency and frustration at yet another third-party breach. Several customers pushed back on the ‘limited breach’ framing, calling it a dark pattern given that nearly all personally identifiable information was in scope, and one veteran flagged that a supposedly unknown zero-day being patched instantly is an unusual pairing.
The more actionable concern is downstream phishing and physical risk. With a known list of names and addresses now circulating, and Framework already sending legitimate ‘update your payment method’ emails that mirror classic phishing — same sender, urgency, and a prominent payment button — customers are exposed to convincing targeted attacks. Users suggested Framework follow Nordic banks in dropping payment links from emails and directing customers to log in directly instead. Others noted that public ‘batch’ order threads tie real identities to high-value laptop deliveries, raising the odds of targeted theft.
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.