Back to Blog
medium severity August 06, 2026 · 4 min read

Framework Notifies Customers of Data Incident via Metabase

If you have an account with Framework, here’s what’s now in circulation.

Framework (computer manufacturer) emailed all customers notifying them of unauthorized access to names, email addresses, phone numbers, and physical addresses stemming from a 0-day vulnerability exploited in its Metabase business-intelligence instance. Metabase disclosed the cloud attack and issued a security update on August 6. Framework began customer notifications the same day; no payment or sensitive order data was accessed.

Framework Notifies Customers of Data Incident via Metabase

Your legal name, home address, and phone number are now publicly exposed and cannot be changed. Because these three pieces of information together create a permanent, verifiable identity profile, the risk you face today is not theoretical and does not expire when the news cycle moves on.

Already exposed?
You can’t unleak a breach. You can take away what it’s worth.
Deep Sweep shows you every leak tied to you and exactly what to change. Then it strips your name, address and family off the look-up sites that turn a leaked record into somebody knocking on your door — $29 one-time, includes 30 days of Protection. We write to 637 companies. No subscription to start.
Scan free, then Deep Sweep — $29 →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

This exposure happened because a business-intelligence platform called Metabase, used internally by Framework, was left accessible with direct read access to live customer records containing that exact combination of data. No passwords were involved. Your account credentials remain secure. What is now loose in the world is the information that lets someone open accounts, request official documents, or target you and your household with high-confidence social engineering and physical threats.

What the Exposed Information Actually Enables

What the Exposed Information Actually Enables

With your full legal name, current or recent home address, and phone number, an attacker can:

  • Build a convincing pretext for phishing emails, SMS messages, or phone calls that appear to come from banks, government agencies, or retailers you actually use.
  • Attempt to reset accounts on other services by using your address and phone number as verification points.
  • Compile a long-term dossier that makes identity theft, tax fraud, or employment fraud easier years from now.
  • Physically locate you or your family with far higher confidence than name alone would allow.

Unlike an email address or password, none of these three data points can be rotated or replaced. Your name, the place you live, and the number tied to your pocket will remain the same. That permanence is what makes this incident different from the usual credential leaks you may have experienced before.

The Metabase Zero-Day That Reached Customer Records

The Metabase Zero-Day That Reached Customer Records

Framework was running an exposed Metabase analytics instance that had been granted broad, direct access to production customer data. The analytics environment was not isolated from live databases, nor was it hardened with network segmentation or strict allow-listing. When a zero-day vulnerability in Metabase was exploited, the attacker could reach exactly the records that should have been off-limits.

Whether the Metabase server was directly reachable from the internet or compromised through another vector is still undisclosed. What is clear is that the company had not applied the basic compensating controls that any organization handling names, addresses, and phone numbers should have in place when using powerful internal analytics tools. The failure was not in password hygiene or customer behavior. It was in infrastructure posture: an analytics layer that could see everything and was not properly firewalled from the outside.

Why Business Intelligence Platforms Keep Becoming Breach Vectors

Analytics and BI tools are granted wide read access to customer databases because that is how they deliver value. When those tools are not isolated, hardened, or placed behind strict network controls, they become high-value targets. A single vulnerability in Metabase, Tableau, Looker, or similar platforms can expose hundreds of thousands of real customer identities in one move.

This pattern has repeated across multiple companies. The lesson for the next incident is simple: if a vendor or internal team tells you their analytics dashboard “just needs database access,” insist on segmentation and least-privilege controls first. That demand, made before the breach, is one of the few preventive steps an individual customer cannot take but can remember when choosing future services.

What You Should Do About Information That Cannot Be Changed

  1. Lock down your phone number. Contact your mobile carrier and add a PIN, passcode, or port freeze to prevent unauthorized SIM swaps or number transfers. This is the single most practical step available for the phone number now circulating.
  2. Place a freeze with all three major credit bureaus. A credit freeze stops new accounts from being opened in your name using the address and identity details now exposed. It is free, reversible, and directly counters the most common follow-on fraud.
  3. Enable alerts on existing financial accounts. Set up transaction notifications and account activity alerts so you see any unusual login or change attempts immediately. The exposed address makes it easier for attackers to pass basic verification questions.
  4. Monitor mail and official correspondence carefully. New credit cards, tax documents, or government mail sent to your address could be intercepted or used as proof of identity. Consider a PO box or secure mail service if your physical mailbox is vulnerable.
  5. Treat any unexpected call, text, or email that references your address as suspicious. With your exact home address public, pretexting becomes significantly more effective. Verify requests through official apps or known phone numbers rather than replying to inbound contact.

These steps will not erase the data that is already loose, but they raise the effort required to abuse it and give you earlier warning when someone tries.

GalaxyWarden provides continuous monitoring across 13.1 billion breach records and more than 100 platforms, identity-chain mapping that connects exposures like this one to future risk, and remediation support from specialists who understand permanent identifiers cannot be reset.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample637 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Framework is one breach. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity Medium
Disclosed August 06, 2026
Affected all customers
Data exposed namesemail addressesphone numbersphysical addresses
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email