Framework customer information was accessed as part of a data breach
Framework's customer database was accessed, but no payment info was released.
Framework, a manufacturer of repairable and upgradeable computers, has informed all its customers that their data was compromised in a breach. The company disclosed via email on August 6 that names, login IPs, addresses, phone numbers and emails were accessed during the attack on business database provider Metabase. Payment information remained untouched in the incident.
The email included Metabase's explanation about the attack, which was identified on August 3, and the measures taken to address it. Metabase revealed that an "unknown (0-day) vulnerability" was exploited, and has now patched the security flaw. The provider's findings and security recommendations are currently preliminary. Framework's security team has rotated credentials and confirmed no alterations in admin access or systems beyond Metabase.
The company is also reviewing and enhancing its data storage methodology in external database vendors. This data breach arrives at a challenging time for Framework, which has been grappling with a memory shortage more than other firms. The company had initially announced price increases in January, followed by further hikes in March.
Shortly after accepting preorders for the new Framework Laptop Pro, the company had to reduce RAM in some preorders due to escalating component costs and to offer full refunds to customers unwilling to pay the increased prices.
Written by urgent.news from Engadget's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.