Framework customer information was accessed as part of a data breach
Framework has told customers that personal information was accessed in a breach involving its business database provider, Metabase. The incident matters because exposed contact and account-related details could be used for phishing or other targeted fraud, although Framework says payment information was not affected.
The accessed data included customer names, login IP addresses, postal addresses, phone numbers and email addresses. Metabase detected the attack on 3 August and said an unknown zero-day vulnerability had been used; it has since been patched, while a third-party forensic investigation continues. Framework says it rotated its credentials and found no unauthorised changes to administrator access or systems outside Metabase.
- Framework customer contact data was exposed through Metabase.
- Payment details were not included in the breach.
- Metabase patched a zero-day vulnerability and is investigating.