Framework customer data leak from compromised Metabase instance
Data Leak
Summary
Hide ▲
Show ▼
Framework confirmed a customer data leak after attackers compromised its Metabase instance, exposing personal and business records tied to customers. The stolen data included full names, email addresses, login IP addresses, billing and shipping addresses, phone numbers, and company names. The exposure raises risk of phishing, account targeting, and identity abuse for affected customers.
Timeline
-
07.08.2026 23:14 2 articles · 1h ago
Customer records stolen from Framework's Metabase instance
Victim Impact UpdateAttackers compromised Framework's Metabase instance on August 3, 2026 and stole customer information, including full names, email addresses, login IP addresses, billing and shipping address information, phone numbers, and company names; some Framework for Business records could also include company name, phone number, VAT, EIN, and billing email address.
Show sources
- Metabase SQLi zero-day exploited in customer data-theft attacks — www.bleepingcomputer.com — 07.08.2026 23:14
- Metabase SQLi zero-day exploited in customer data-theft attacks — www.bleepingcomputer.com — 07.08.2026 23:14
-
06.08.2026 03:00 1 articles · 1d ago
Framework is notified that attackers accessed its Metabase instance
Initial DisclosureMetabase notified Framework on August 6, 2026 that its instance had been vulnerable to the zero-day and accessed by an attacker on August 3, 2026, and Framework then disclosed that the incident allowed attackers to steal customer information.
Show sources
- Metabase SQLi zero-day exploited in customer data-theft attacks — www.bleepingcomputer.com — 07.08.2026 23:14