Framework reports a Framework data breach at business intelligence provider Metabase that exposed customer contact data. The company shared the notice on the Framework Community. Framework says payment and order records stay out of the accessed set. Metabase also published a security update about a zero-day on Metabase Cloud.
Meanwhile, Framework told customers the notice covers everyone whose information sat in the affected Metabase instance. A company spokesperson also told press that the incident reaches all customers. That does not mean thieves stole payment cards. It does mean names, emails, phones, and shipping details now fuel phishing and social engineering risk.
What Framework says attackers reached
Framework says it reviewed logs Metabase provided and confirmed access to a set of fields. Those fields include full name, email address, and login IPs. Billing and shipping address blocks also appear: country, street address, city, state, ZIP, phone, and company. For Framework for Business accounts, the company still checks company phone, VAT, EIN, and billing email.
Importantly, Framework says attackers did not reach other personally identifiable information, order information, or payment information. That claim matters for customers watching bank statements. It is not a free pass for email-based fraud.
How Metabase describes the attack
Metabase says someone hit Metabase Cloud with an unknown zero-day in versions 1.58 and above. The vendor blocked the attack endpoints, then patched the flaw. Metabase says it already upgraded Cloud customers. Self-hosted operators on vulnerable versions should upgrade immediately and rotate connected database credentials.
Additionally, Metabase documents an attack pattern around password-reset endpoints. The pattern involves a call to POST /api/session/reset_password followed by GET /api/user/current. A related GitHub security advisory tracks the issue. Metabase also notes an ongoing investigation and treats early updates as preliminary.
What Framework did next
After Metabase’s notice on August 6, Framework rotated credentials on databases tied to its Metabase instance. The company says it found no admin-access changes and no access to systems outside Metabase. Framework also reviews how much data it shares with external business intelligence tools. It plans to narrow column access to analysis needs only.
However, customers should still treat unexpected Framework-branded mail carefully. Attackers who hold names, emails, addresses, and phones can craft believable support scams. Customers should check official messages against the real sender domain. They should also check account activity inside Framework’s own site, not only through surprise mail links.
Tech My Money has covered related platform security stories, including OpenAI agent evaluation breakouts and Kimi K3 sandbox network egress reporting.
What customers should watch
Finally, Framework says it will send a follow-up if Metabase reports additional impact. Customers should watch for unexpected login attempts and identity scams that reuse leaked contact data. Framework did not list payment cards among accessed fields. Still, password reuse and MFA remain the baseline for any account that shared those emails.













































