Skip to content
Back to Blog
medium severity August 06, 2026 · 4 min read

Framework Notifies Customers of Data Incident via Metabase

If you received a notice from Framework, here’s what the filing says was exposed, and what to do about it.

Framework (computer manufacturer) emailed all customers notifying them of unauthorized access to names, email addresses, phone numbers, and physical addresses stemming from a 0-day vulnerability exploited in its Metabase business-intelligence instance. Metabase disclosed the cloud attack and issued a security update on August 6. Framework began customer notifications the same day; no payment or sensitive order data was accessed.

Framework Notifies Customers of Data Incident via Metabase

Your legal name, home address, and phone number are now publicly exposed and cannot be changed. Because these three pieces of information together create a permanent, verifiable identity profile, the risk you face today is not theoretical and does not expire when the news cycle moves on.

This exposure happened because a business-intelligence platform called Metabase, used internally by Framework, was left accessible with direct read access to live customer records containing that exact combination of data. No passwords were involved. Your account credentials remain secure. What is now loose in the world is the information that lets someone open accounts, request official documents, or target you and your household with high-confidence social engineering and physical threats.

What the Exposed Information Actually Enables

What the Exposed Information Actually Enables

With your full legal name, current or recent home address, and phone number, an attacker can:

  • Build a convincing pretext for phishing emails, SMS messages, or phone calls that appear to come from banks, government agencies, or retailers you actually use.
  • Attempt to reset accounts on other services by using your address and phone number as verification points.
  • Compile a long-term dossier that makes identity theft, tax fraud, or employment fraud easier years from now.
  • Physically locate you or your family with far higher confidence than name alone would allow.

Unlike an email address or password, none of these three data points can be rotated or replaced. Your name, the place you live, and the number tied to your pocket will remain the same. That permanence is what makes this incident different from the usual credential leaks you may have experienced before.

The Metabase Zero-Day That Reached Customer Records

The Metabase Zero-Day That Reached Customer Records

Framework was running an exposed Metabase analytics instance that had been granted broad, direct access to production customer data. The analytics environment was not isolated from live databases, nor was it hardened with network segmentation or strict allow-listing. When a zero-day vulnerability in Metabase was exploited, the attacker could reach exactly the records that should have been off-limits.

Whether the Metabase server was directly reachable from the internet or compromised through another vector is still undisclosed. What is clear is that the company had not applied the basic compensating controls that any organization handling names, addresses, and phone numbers should have in place when using powerful internal analytics tools. The failure was not in password hygiene or customer behavior. It was in infrastructure posture: an analytics layer that could see everything and was not properly firewalled from the outside.

Why Business Intelligence Platforms Keep Becoming Breach Vectors

Analytics and BI tools are granted wide read access to customer databases because that is how they deliver value. When those tools are not isolated, hardened, or placed behind strict network controls, they become high-value targets. A single vulnerability in Metabase, Tableau, Looker, or similar platforms can expose hundreds of thousands of real customer identities in one move.

This pattern has repeated across multiple companies. The lesson for the next incident is simple: if a vendor or internal team tells you their analytics dashboard “just needs database access,” insist on segmentation and least-privilege controls first. That demand, made before the breach, is one of the few preventive steps an individual customer cannot take but can remember when choosing future services.

What You Should Do About Information That Cannot Be Changed

  1. Lock down your phone number. Contact your mobile carrier and add a PIN, passcode, or port freeze to prevent unauthorized SIM swaps or number transfers. This is the single most practical step available for the phone number now circulating.
  2. Place a freeze with all three major credit bureaus. A credit freeze stops new accounts from being opened in your name using the address and identity details now exposed. It is free, reversible, and directly counters the most common follow-on fraud.
  3. Enable alerts on existing financial accounts. Set up transaction notifications and account activity alerts so you see any unusual login or change attempts immediately. The exposed address makes it easier for attackers to pass basic verification questions.
  4. Monitor mail and official correspondence carefully. New credit cards, tax documents, or government mail sent to your address could be intercepted or used as proof of identity. Consider a PO box or secure mail service if your physical mailbox is vulnerable.
  5. Treat any unexpected call, text, or email that references your address as suspicious. With your exact home address public, pretexting becomes significantly more effective. Verify requests through official apps or known phone numbers rather than replying to inbound contact.

These steps will not erase the data that is already loose, but they raise the effort required to abuse it and give you earlier warning when someone tries.

GalaxyWarden provides continuous monitoring across 13.1 billion breach records and more than 100 platforms, identity-chain mapping that connects exposures like this one to future risk, and remediation support from specialists who understand permanent identifiers cannot be reset.

Report details & sourcing

Severity Medium contact details only, none of them permanent
Disclosed August 06, 2026
Last reviewed August 6, 2026
Affected all customers
Data exposed namesemail addressesphone numbersphysical addresses
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email