Framework Notifies Customers of Data Incident via Metabase
If you have an account with Framework, here’s what’s now in circulation.
Framework (computer manufacturer) emailed all customers notifying them of unauthorized access to names, email addresses, phone numbers, and physical addresses stemming from a 0-day vulnerability exploited in its Metabase business-intelligence instance. Metabase disclosed the cloud attack and issued a security update on August 6. Framework began customer notifications the same day; no payment or sensitive order data was accessed.
Your legal name, home address, and phone number are now publicly exposed and cannot be changed. Because these three pieces of information together create a permanent, verifiable identity profile, the risk you face today is not theoretical and does not expire when the news cycle moves on.
This exposure happened because a business-intelligence platform called Metabase, used internally by Framework, was left accessible with direct read access to live customer records containing that exact combination of data. No passwords were involved. Your account credentials remain secure. What is now loose in the world is the information that lets someone open accounts, request official documents, or target you and your household with high-confidence social engineering and physical threats.
What the Exposed Information Actually Enables
With your full legal name, current or recent home address, and phone number, an attacker can:
- Build a convincing pretext for phishing emails, SMS messages, or phone calls that appear to come from banks, government agencies, or retailers you actually use.
- Attempt to reset accounts on other services by using your address and phone number as verification points.
- Compile a long-term dossier that makes identity theft, tax fraud, or employment fraud easier years from now.
- Physically locate you or your family with far higher confidence than name alone would allow.
Unlike an email address or password, none of these three data points can be rotated or replaced. Your name, the place you live, and the number tied to your pocket will remain the same. That permanence is what makes this incident different from the usual credential leaks you may have experienced before.
The Metabase Zero-Day That Reached Customer Records
Framework was running an exposed Metabase analytics instance that had been granted broad, direct access to production customer data. The analytics environment was not isolated from live databases, nor was it hardened with network segmentation or strict allow-listing. When a zero-day vulnerability in Metabase was exploited, the attacker could reach exactly the records that should have been off-limits.
Whether the Metabase server was directly reachable from the internet or compromised through another vector is still undisclosed. What is clear is that the company had not applied the basic compensating controls that any organization handling names, addresses, and phone numbers should have in place when using powerful internal analytics tools. The failure was not in password hygiene or customer behavior. It was in infrastructure posture: an analytics layer that could see everything and was not properly firewalled from the outside.
Why Business Intelligence Platforms Keep Becoming Breach Vectors
Analytics and BI tools are granted wide read access to customer databases because that is how they deliver value. When those tools are not isolated, hardened, or placed behind strict network controls, they become high-value targets. A single vulnerability in Metabase, Tableau, Looker, or similar platforms can expose hundreds of thousands of real customer identities in one move.
This pattern has repeated across multiple companies. The lesson for the next incident is simple: if a vendor or internal team tells you their analytics dashboard “just needs database access,” insist on segmentation and least-privilege controls first. That demand, made before the breach, is one of the few preventive steps an individual customer cannot take but can remember when choosing future services.
What You Should Do About Information That Cannot Be Changed
- Lock down your phone number. Contact your mobile carrier and add a PIN, passcode, or port freeze to prevent unauthorized SIM swaps or number transfers. This is the single most practical step available for the phone number now circulating.
- Place a freeze with all three major credit bureaus. A credit freeze stops new accounts from being opened in your name using the address and identity details now exposed. It is free, reversible, and directly counters the most common follow-on fraud.
- Enable alerts on existing financial accounts. Set up transaction notifications and account activity alerts so you see any unusual login or change attempts immediately. The exposed address makes it easier for attackers to pass basic verification questions.
- Monitor mail and official correspondence carefully. New credit cards, tax documents, or government mail sent to your address could be intercepted or used as proof of identity. Consider a PO box or secure mail service if your physical mailbox is vulnerable.
- Treat any unexpected call, text, or email that references your address as suspicious. With your exact home address public, pretexting becomes significantly more effective. Verify requests through official apps or known phone numbers rather than replying to inbound contact.
These steps will not erase the data that is already loose, but they raise the effort required to abuse it and give you earlier warning when someone tries.
GalaxyWarden provides continuous monitoring across 13.1 billion breach records and more than 100 platforms, identity-chain mapping that connects exposures like this one to future risk, and remediation support from specialists who understand permanent identifiers cannot be reset.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Everest ransomware claims breach of Liberty Mutual insurance data
The Everest ransomware group listed Liberty Mutual on its leak site, claiming theft of over 100 GB o…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
149 Million Credential Mega-Exposure — January 2026
Security researchers discovered a publicly exposed 96 GB database with 149 million unique logins cov…