Security Breach: Framework Customers’ Personal Information Exposed Through Metabase

A security breach involving Framework’s business-intelligence provider Metabase has exposed personal information belonging to Framework customers, including names, email addresses, phone numbers, login IPs, and billing and shipping addresses.

The incident began with an attack against Metabase Cloud on August 3, 2026. Metabase said an attacker exploited an unknown zero-day vulnerability affecting its cloud service. The company blocked the attack endpoints, identified and patched the vulnerability, notified law enforcement, and began a forensic investigation.

Framework later confirmed that its Metabase database instance had been accessed. The company reviewed the activity information provided by Metabase and identified the customer information that the attacker accessed.

Framework has described its customer notification as preliminary. The company is working with an outside forensic investigation firm to determine the full scope of the incident.

What Happened in the Security Breach

The incident centered on Metabase, a business-intelligence platform used by companies to analyze business data.

On August 3, Metabase discovered that an attacker had compromised its cloud environment by exploiting a previously unknown vulnerability. Metabase described the flaw as a zero-day vulnerability.

The attack affected Metabase Cloud instances running vulnerable versions beginning with version 1.58.

After detecting the attack, Metabase blocked the endpoints used by the attacker. Its security team then identified and patched the vulnerability.

Metabase also notified law enforcement and hired an independent forensic firm to investigate what happened.

The company informed affected customers that attackers had gained access to their Metabase instances. It recommended that affected organizations rotate credentials for databases connected to their Metabase environments and review administrative accounts for anything unfamiliar.

Framework was among the organizations whose Metabase environment was affected.

Framework Confirms Customer Data Was Accessed

Framework received notification from Metabase on August 6.

The computer manufacturer then reviewed the logs and other information provided by Metabase. That investigation confirmed that Framework’s Metabase database instance had been accessed.

Framework identified several categories of information that were accessed during the incident.

The confirmed information includes:

  • Full names
  • Email addresses
  • Login IP addresses
  • Phone numbers
  • Billing addresses
  • Shipping addresses
  • Country information
  • City information
  • State information
  • ZIP codes
  • Company information

Framework said the incident did not involve order information or payment information.

That distinction is significant for customers because the available information does not indicate that credit-card or other payment details were exposed through the Metabase incident.

The investigation remains active, however, so Framework has not presented its current findings as the final assessment.

Business Customers May Have Additional Information Involved

Framework also identified a separate set of information connected to Framework for Business customers.

The company is investigating whether attackers may have accessed:

  • Company information
  • Business phone numbers
  • VAT information
  • EIN information
  • Billing email addresses

Framework has not confirmed that all of these additional categories were accessed.

Instead, the company has said it is investigating whether they may have been exposed.

That distinction matters when describing the incident. Confirmed customer information and information still under investigation should not be treated as the same thing.

The company has therefore continued to describe its findings as preliminary while the forensic review continues.

Read More – Arc Raiders Security Breach: December 2025 Update on Player Data Safety and Developer Response

Payment Information Was Not Part of the Breach

One of the clearest findings from Framework’s investigation concerns payment information.

Framework said no payment information was accessed during the incident.

The company also said no order information was accessed.

Customers therefore should not interpret the incident as evidence that their Framework payment-card details were stolen.

The information that was confirmed as accessed mainly consists of identity and contact information.

That data can still have security and privacy consequences, particularly when several categories appear together.

A person’s name, email address, phone number and physical address can give an attacker enough information to make fraudulent communications appear legitimate.

Why the Exposed Information Matters

Names and email addresses are common pieces of information, but their combination with other personal details can increase the risk of targeted scams.

For example, a person who knows a customer’s name and address may be able to make a fraudulent email or phone call sound more credible.

An exposed phone number can also become a target for unwanted calls or text messages.

Email addresses can be used in phishing campaigns designed to trick recipients into revealing passwords, account details or financial information.

The presence of login IP addresses adds another category of technical information to the exposed data.

Framework has not said that customers’ accounts were taken over as a result of the incident.

It also has not reported that payment credentials were exposed.

Customers should therefore focus on the confirmed facts rather than assume that every account associated with their personal information has been compromised.

Framework Rotated Database Credentials

After receiving the incident notification from Metabase, Framework rotated credentials for databases connected to its Metabase environment.

The company also reviewed administrative access.

Framework said it confirmed that there were no changes to administrative access and no access to systems outside of Metabase.

Those findings help define the current scope of the incident.

The confirmed compromise involved the Metabase environment used for business intelligence. Framework has not reported a broader compromise of its systems.

The company continues to work with investigators to establish whether any additional activity occurred.

Metabase Patched the Vulnerability

Metabase acted after discovering the attack.

The company blocked the endpoints associated with the attack and identified the vulnerability that allowed the unauthorized access.

Metabase then patched the flaw.

The company also advised affected customers to rotate credentials for databases connected to their instances.

Administrators were encouraged to review their accounts and remove anything they did not recognize.

These actions are particularly important for organizations using analytics platforms that connect directly to internal databases.

A business-intelligence system can contain or access large amounts of operational information. Protecting those connections can therefore become an important part of an organization’s overall security strategy.

The Investigation Has Not Finished

Framework has repeatedly emphasized that its current findings are preliminary.

The company is working with a third-party forensic investigation firm to determine the full nature and scope of the incident.

Metabase is also conducting its own investigation.

The two investigations are important because the first notification may not provide a complete picture of every action performed by an attacker.

Forensic investigators can examine application logs, database activity and other technical records to determine what occurred.

Framework has indicated that it will provide additional information if the investigation produces findings that affect customers.

Until then, confirmed information should remain separate from unverified claims.

Timeline of the Incident

The known timeline provides a clear picture of how the incident developed.

DateConfirmed event
August 3, 2026Metabase discovered an attack against Metabase Cloud.
August 3, 2026Metabase blocked the endpoints used in the attack.
August 3, 2026Metabase identified and patched the vulnerability.
August 3 onwardMetabase began its investigation and notified affected organizations.
August 6, 2026Framework received notification from Metabase.
August 6 onwardFramework reviewed logs and confirmed unauthorized access to its Metabase database instance.
August 6 onwardFramework rotated credentials and reviewed administrative access.
August 9, 2026Framework’s forensic investigation remains ongoing.

The timeline may change if investigators release additional confirmed findings.

What Framework Customers Should Know

Customers who received a notification from Framework should understand the difference between the information that was confirmed as accessed and the information that remains under investigation.

The confirmed categories include names, email addresses, login IPs, phone numbers, company information and billing and shipping address details.

Payment information and order information were not accessed, according to Framework’s investigation.

The company has not reported unauthorized access to systems outside its Metabase environment.

Framework also said it found no changes to administrative access.

These points provide the clearest current picture of what customers face.

Watch for Suspicious Messages

Customers whose information was included in the affected database should remain cautious about unexpected communications.

A message containing a person’s real name, address or phone number can still be fraudulent.

Customers should be especially careful with messages that:

  • Request account passwords
  • Ask for payment information
  • Request verification codes
  • Contain unexpected account-reset links
  • Claim there is an urgent shipping problem
  • Ask recipients to download unfamiliar files
  • Request personal information by text
  • Ask for sensitive information over the phone

Customers should not assume that a message is legitimate simply because it contains accurate personal information.

If someone claims to represent Framework, customers can independently access the company’s official website rather than relying on links supplied in an unexpected message.

The Difference Between a Data Exposure and Payment Theft

The incident illustrates why a data breach does not always mean payment information has been stolen.

Framework’s notification identifies personal and contact information as the data accessed through its Metabase environment.

The company separately states that payment information and order information were not accessed.

That means customers should not automatically cancel payment cards or assume that their financial information was exposed because they received a breach notification.

However, the exposed information can still create privacy concerns.

Personal details can remain useful to criminals long after a vulnerability has been patched.

That makes caution around suspicious communications an important response for affected customers.

Third-Party Technology Played a Central Role

The Framework incident occurred through a third-party business-intelligence provider rather than through a reported compromise of Framework’s primary systems.

Framework used Metabase to support business intelligence and data analysis.

That arrangement required information to be available within the analytics environment.

When the Metabase environment was compromised, information stored there became accessible to the attacker.

This type of incident demonstrates why companies must consider the security of external technology providers when protecting customer information.

A business may secure its own systems while still relying on vendors for analytics, cloud services, customer management and other functions.

Each additional service can create another environment that requires appropriate access controls.

Framework Is Reviewing Its Data Practices

Framework said it is reviewing the amount and type of information shared with business-intelligence platforms.

The company is also looking at ways to limit analytics systems to only the database columns needed for their specific functions.

That approach can reduce the amount of customer information available through an external service.

If an analytics platform does not require a particular data field, restricting its access can reduce the potential impact of a future compromise.

Framework’s review follows its confirmation that customer information was accessed through its Metabase environment.

The company has not announced that all future analytics arrangements will follow a particular structure, but it has said it is evaluating the breadth and depth of data shared with business-intelligence services.

What Remains Unknown

Several important questions remain open while the investigation continues.

Framework has not published a final determination of the total number of affected customers.

It has also not completed its forensic investigation into the incident.

The company is still examining whether certain information associated with Framework for Business customers was accessed.

Additional findings could clarify the full scope of the event.

At this stage, it would be inaccurate to claim that more information was stolen unless Framework or investigators confirm it.

The same applies to claims about additional affected organizations or customers.

The investigation needs to establish those facts before they can be treated as confirmed.

What Customers Can Do Now

Framework customers can take several straightforward precautions without assuming that their financial information was compromised.

Review unexpected emails and text messages carefully.

Avoid clicking suspicious links, particularly when a message creates an urgent request.

Use unique passwords for important online accounts.

Enable multifactor authentication when available.

Customers should also be cautious when receiving phone calls that use personal information to establish credibility.

If a caller already knows a person’s name, address or phone number, that does not prove that the caller represents a legitimate company.

People should independently verify requests involving passwords, payment information or account credentials.

These precautions are particularly relevant after a breach involving contact and address information.

Current Status of the Incident

As of August 9, 2026, Framework’s investigation remains ongoing.

The company has confirmed unauthorized access to its Metabase database instance.

It has also identified customer names, email addresses, login IPs, phone numbers and billing and shipping information among the data accessed.

Framework has confirmed that order and payment information were not accessed.

The company rotated database credentials after receiving the incident notification and reviewed administrative access.

Framework also said it found no access to systems outside the Metabase environment.

Metabase has patched the vulnerability that enabled the attack and continues to investigate the incident with outside forensic assistance.

The final scope could become clearer as investigators review additional technical evidence.

For now, customers should rely on confirmed information and remain alert for suspicious communications that use their exposed contact details.

Framework customers have clear reasons to stay cautious, but the confirmed findings also show that payment and order information were not accessed in this incident.

Old-Age and Survivors Insurance...

The Old-Age and Survivors Insurance and Disability Insurance funds...

2026 Social Security Trustees...

The 2026 Social Security Trustees Report, released June 9,...

Planning to Retire in...

Anyone planning to retire in 2030 is entering the...

X-Men Movies in Order:...

Figuring out the X-Men movies in order can feel...

Wolverine and the X-Men:...

Wolverine and the X-Men remains one of the most...

New York State Police...

The New York State Police is leading a multi-agency...