Framework discloses data breach via Metabase 0-day

RobinHirst114 pts0 comments

Framework Data Breach Discussion - General Topics - Framework Community

= 40rem)" rel="stylesheet" data-target="discourse-ai_desktop" /><br>= 40rem)" rel="stylesheet" data-target="discourse-calendar_desktop" /><br>= 40rem)" rel="stylesheet" data-target="discourse-reactions_desktop" /><br>= 40rem)" rel="stylesheet" data-target="poll_desktop" />

Framework Data Breach Discussion

General Topics

marsmathis

August 6, 2026, 10:37pm

I just received an email about a limited data breach, leaking customer information (no billing info though). Do you guys think Framework is handling this well? The email looked very detailed and transparent to me.

4 Likes

Alex_Shoup

August 7, 2026, 12:38am

The transparency and especially the expediency of notification is greatly appreciated, I’d say not only by the Framework team but also by Metabase. A 3 day turnaround by Metabase from initial discovery of the incident to notify business partners is impressive. And the Framework team took only 6 HOURS from receiving Metabase’s notice before internally confirming and notifying their customers!! That is unheard of!! It seems like most companies wait months (at minimum) before notifying customers (if they do at all) because they think any security issue will cause the public to lose trust in them.

These days, it’s not a matter of when you suffer a security incident. It’s how quickly and transparently you respond to it and notify your customers. In my opinion, the Framework team far exceeded expectations, and I anticipate any updates will be met with the same level of transparency. Other companies need to take note, this is how you handle a security incident.

2 Likes

Nick_Debord

August 7, 2026, 12:53am

Credit card info. Need assurance that was not accessed by the hackers.

Alex_Shoup

August 7, 2026, 1:16am

Their privacy policy states Stripe is used for handling payments, and it was already stated in the email there was no payment information.

image593×306 29.7 KB

1 Like

Chironjit_Das

August 7, 2026, 2:36am

Its disappointing another company has chosen to share our personal information with another third party. While at this point I think all of my information has probably already been leaked, I still do not appreciate my data being shared with third party providers. Getting all your personal information leaked because a company you have never heard of or interacted with is getting insanely normalised.

4 Likes

skorov

August 7, 2026, 4:04am

While I appreciate Framework’s notice and transparency (moreso than most orgs), I can’t say it’s not frustrating to be part of yet another data breach. Maybe we stop sharing so much data with 3rd parties??

3 Likes

Alk

August 7, 2026, 4:28am

I agree. Communication at this level is appreciated. The fact remains that Framework is benefiting from storing our data with a 3rd party for whatever vague analysis they decide to use it for and we bear the consequences of having certain data exposed when it shouldn’t be.

From Framework’s Notice:

What steps have you taken to ensure this doesn’t happen in the future?

We are evaluating the breadth and depth of data shared with business intelligence platforms, and scoping down their access to only the columns required for analysis.

Obviously this is moving in the right direction, but it may reveal that the depth of information previously shared with this platform was excessive to begin with.

Henrikas

August 7, 2026, 5:00am

Appreciate the transparency, but I do not appreciate the wording of the messaging. Calling this a “limited” breach right in the email subject is quite dishonest when basically all the personally identifiable information is there.

Also the email lists all the personally identifiable information and then it says “no other personally identifiable information has been taken”. Yeah, that’s all you had! This feels like a dark pattern of communication. You can do better, framework.

Also, does the business side have to have names, emails of the customers? Also, of course it sucks that only now you’re starting to ask these questions…

1 Like

ontheroad

August 7, 2026, 5:28am

I got the breach notification today. Earlier this week I got an “Action Required” email asking me to update my payment method before my laptop would ship.

I always handle emails like these by ignoring the button and logging in directly at the relevant website (this time Framework). It worked out well, and the email was clearly legitimate.

But I’d like to flag the pattern. A phishing email built off the breached data would look almost exactly like the one I received: same sender name, same layout, same urgency, same big button to update payment information.

I understand that Framework likely will not strip the link entirely, as it will make the friction of updating payment info too much for some users. But I would suggest that the email primarily asks the customer to log in through the web site and not through a link.

Most Nordic banks dropped payment...

data framework information august email breach

Related Articles