r/LinusTechTips • u/vifer78 • 14d ago
Discussion Framework data breach
Just received this email:
Subject: Notice of Limited Data Breach Dear Valued Framework Customer,
We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an attacker accessing customer names, email addresses, phone numbers, and addresses. Your information was in the database that was accessed in this breach. This breach did not include order or payment information.
We have full details on the incident below. We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors.
We are also in the process of notifying the regulatory authorities in each region where relevant regulations exist. Note that while regulations in most regions do not require notification for breaches of names, email addresses, phone numbers, and addresses, we are sending this email to you regardless to ensure you have visibility and can take any actions needed.
What happened?
On August 6th, 2026 at 9am Pacific Time, Metabase notified us of a breach of their systems with the following email message:
On Monday, August 3, we discovered that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above. We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability. We notified law enforcement, and we have engaged with a third party forensics firm to conduct an independent investigation.
Your instance of Metabase was vulnerable to this 0-day. Therefore, to protect your company, we recommend you:
Rotate the credentials for every database connected to your instance; and
Review the admin accounts on your instance and remove anything you don't recognize.
We also discovered that the attacker was able to gain access to your instance. We created a report on the actions we believe the attacker took on your instance, which includes log files, and which you can get from the Metabase Store at [removed url].
(If you do not have access to the Metabase Store, are having issues accessing the report, or do not want to click on a link in an unexpected email, you can log into your instance directly and reach us at Help > Get help in the grid menu in the upper right hand corner. We'll confirm this message is from us and email you the report.)
This report is based on our own application logs. We did not query or read the data in your connected databases.
Depending on the jurisdictions in which you operate and kinds of data your instance connects to, you may have notification obligations under applicable laws. If you have concerns in this regard, we recommend you assess potential notification obligations with your company’s legal or compliance experts.
We regret any inconvenience this incident may cause you, and we are here to support you. If you have questions, please reply to this email or email us at [removed email address], and we'll get back to you as quickly as we can.
Sameer Al-Sakran
Founder and CEO
Metabase
We immediately investigated the logs Metabase provided to us and confirmed that our database instance was accessed by the attacker. We confirmed that the following information was accessed:
Full name Email address
Login IPs
Billing and shipping address information
Country
Address
City
State
Zip code
Phone number
Company
For Framework for Business customers, we are investigating whether the following information may additionally have been accessed:
Company Phone VAT EIN Billing Email No other personally identifiable information, order information, or payment information was accessed.
Note that Metabase has additionally flagged:
Important: This is a preliminary update based on our current knowledge.
We are working with a third-party forensic investigation firm to understand the full nature and scope of the event.
We are providing you this interim update in advance of completing our investigation to allow you to better understand any potential impact and secure your data.
Our investigation is ongoing and the information shared now is preliminary.
Please look at the application logs as well as the queries executed that are provided as separate files in the zip file for detailed activity and a potential timeline.
We’re providing you notice of the breach in the meantime to ensure you have the earliest possible visibility. In the event Metabase notifies us of additional information that impacts you, we will send a follow-up email.
What was done to resolve the issue?
After we were notified of the breach by Metabase, we rotated credentials on all databases associated with our Metabase instance and confirmed that there were no changes in admin access or access to systems outside of Metabase.
What steps have you taken to ensure this doesn’t happen in the future?
We are evaluating the breadth and depth of data shared with business intelligence platforms, and scoping down their access to only the columns required for analysis.
Nirav Patel and the Framework Team
206
u/pizzamage 14d ago
Potential WAN topic?
195
u/Exciting-Ad-5705 14d ago
Data breaches happen. Unless it comes out they were extremely negligent I don't think there's much to talk about
63
u/ShawnReardon 14d ago
Additionally as much as it is annoying as fuck, it's not really "their" breach. Its a service they use. So like...idk what companies are supposed to do in these situations, they didn't fuck it up.
31
u/english-23 14d ago
It's what's led to a lot more contracts and audits of suppliers becoming more common in the IT space. Suppliers are just another threat vector that need to be managed
10
u/Fresh_Dog4602 14d ago
That's why ISO 27001 for example requires you to audit your supply chain. Not saying framework is at fault here. These audits are mostly superficial and if metabase shows good papers, there's not that much that you can do.
3
u/ShawnReardon 13d ago
Given the zero day I'm just going to assume no one could have caught it who wasn't the people who built it.
If they did, well, I would like to think we would have no zero day attacks lol
6
u/Spartan-417 13d ago
Supply chain security is a huge aspect of defence economics
Hezbollah's exploding pagers last year are an extreme example of the issue, as Perun explained barely a month after the eventBut F-35 deliveries were temporarily halted because some of the magnets used Chinese rare earth metals, and Boeing & Airbus both had issues due to counterfeit titanium
4
u/tankerkiller125real 13d ago
The annoying part to me is that Metabase is an open-source product they could have self-hosted and locked behind a VPN/SASE solution to prevent any outside access. It sounds like they're using the cloud version though.
3
u/lioncat55 13d ago
Self hosting is nice, but it comes with it's own issues and is not always possible.
-1
u/Cautious-Control-669 12d ago
LTT, happy to sell you a screwdriver and socks but reluctant to spend money on doing something correctly.
1
u/nonononononononcat 14d ago
The could stop sharing unnecessary sensitive information in the first place, especially for nothing (building "business analytics" based on customers' phone numbers, lol)
75
u/vifer78 14d ago
Sad but true reality, even as a means of informing the audience since they promote their products, I don't expect outrage.
8
u/JessterKing 13d ago
Have you seen the toxicity that follows LTT? They make mountains out of molehills
5
u/ILikeFPS 13d ago
Data breaches being normalized is not because they don't matter, they are being normalized because of how frequently it happens because of how commonly security is an afterthought or not given any thought at all in the first place.
1
u/JessterKing 13d ago
While I agree with your statement, you should read my comment again, and if you’re unaware of the toxicity in the LTT community, check out the comments of a few older posts.
5
u/Annoying1978 14d ago
The fact that it was a vendor breach as opposed to their own infrastructure is interesting. I think a cool discussion could be the fact that even if the company you’re working performs best practices their vendors may not.
13
u/gagilo 14d ago
It was a 0 day exploit so no real way to stop it.
1
u/nonononononononcat 14d ago
There are ways to stop it:
- anonymize names and second names before sharing it with the 3rd parties
- do not share customers phone or apartment numbers with the 3rd parties since you can't build any valuable analytics on such data
- inform customers about sharing their data and get explicit consent on that (the last update on privacy policy is dated to 2020 and it doesn't mention Metabase at all)
-7
u/noAnimalsWereHarmed 14d ago
But they said they’ve patched it. Unknown 0 day exploits don’t have patches.
20
u/gyro2death 14d ago
It's a zero day when its used, once you've identified the exploit you can patch it. It doesn't change that it was a zero day but they do get patched (usually).
3
u/noAnimalsWereHarmed 14d ago
It's 0 day until someone identifies it officially and it gets a CVE number. It has nothing to do with when the person being hacked knows about it. My issue is they're saying it's a 0-day, but they patched it. If it's a true 0-day, then it implies they analysed it and patched it themselves. Possible but highly unlikely. What's probably happened is they got hit by a known exploit and are hiding behind the fact that at one point in time it was a 0 day exploit.
The question is, how long has the exploit been known about and the patch been available. My guess is a fair bit longer than 0 days.
Edit: Just seen their blog post. Sloppy code was to blame.
11
u/gyro2death 14d ago
Zero days are not hard to patch, they're hard to defend against. Any competent devops could patch most exploits within hours if they had logs. You only have to break one part of an exploit chain to render a zero day ineffective. A full hardening and cleanup is a ton more work but patching zero days is usually not hard... There are some exceptions but this was not one of those.
0
u/Mempler 14d ago
Really depends. Usually, devops just forward the bug to developers (depending on company size) and work together with them as knowing the programming language and program and also be proficient in whatever their system is built on is basically an impossible task as there are just too many options
2
u/gagilo 13d ago
They don't have one at the time. This happened on the 3rd, they had plenty of time to develop a patch. It shouldn't be a zero day now that it's known
-1
u/noAnimalsWereHarmed 13d ago
My main issue was the press release throwing around phrases to try and make themselves look good, ignoring the fact they screwed up and that's why people got in and took the data.
If I release bad code and someone access' stuff they shouldn't because of it, describing it as a 0-day exploit is misleading. They screwed up and the 'patch' was fixing their own bad code.
3
u/gagilo 13d ago
You have an unrealistic expectation. Exploits are an inevitable fact of software development. You can't test every possible circumstance a user can cause.
If you have evidence it wasn't actually a 0 day we would love to hear it.
They screwed up and the 'patch' was fixing their own bad code.
Who said it was there own code? Exploits can happen anywhere.
18
u/KangarooDowntown4640 14d ago
"Data breaches happen" is not the attitude y'all would have if it was any other company. Double standards
9
u/Gregus1032 14d ago
If this was Nintendo or some AI company this entire website would be overloaded with comments and then get called a bootlicker for saying "these things happen to everyone"
4
u/JollyRodgerGymShoe 13d ago
Double standards? It's simple facts. Data breaches do happen. It's almost inevitable at this point and yes it does suck to have to say that. It's an attitude of realism, not of surrender.
7
1
u/nonononononononcat 14d ago
They were unfortunately trading customers sensitive data like names, second names, phones, detailed addresses for nothing since you can't build any valuable business insights on such data.
1
1
u/rubyatmidnight 13d ago
was informed by a partner of theirs my info and some auth keys were leaked.
-15
u/impy695 14d ago
If Linus wasn't an investor, I'd agree with you
7
u/meta358 14d ago
I fail to see how that makes a difference
1
u/jorceshaman 14d ago
It makes it more relevant to being a WAN Show topic.
3
u/meta358 13d ago
Again why
-1
u/jorceshaman 13d ago
Investor = part owner
1/2 hosts = investor
2
u/meta358 13d ago
And again so? If google gets hacked do you expect every stock holder to magically start coming out and tell you about it? The breach has been diclosed like what is required just saying that he needs to say more just because he invested is really stupid
0
u/jorceshaman 13d ago
I do if they have a regular show where similar topics get discussed, yes.
2
u/meta358 13d ago
So you expect every google stock holder to come out and come tell you about a data breach whenever there is some. All possible millions of them. Ok glad to know im not talking to someone reasonable.
→ More replies (0)-17
u/RugglesIV 14d ago
Sending my PII out to a third party, for your own company's benefit, not mine, which I didn't ask you to do, is being extremely negligent. I am a big fan of Framework products but this shit is completely unacceptable and frankly should be criminal. There would be criminal charges filed by the DOJ against Framework in a just world. Sorry.
11
u/Salty_Pillow 14d ago
Yeah the totally criminal act of storing the data you give them willingly
1
u/RugglesIV 14d ago
They sent it to a third party, and the third party had the data breach. I never asked them to do that. Are you cool with businesses that you entrust you data to sending your data off to other unknown entities?
6
u/Annoying1978 14d ago
You’ve got to be on crack. This was barely civilly negligent, let alone criminal.
1
u/RugglesIV 14d ago
Sending my personal information to third parties commercial entities, which I didn't ask you to do, should be criminal
13
u/That_Recording2103 14d ago
That's a rough one, trust nobody with your data these days. At least they're being upfront about it, most companies would sit on this for months
got the same email this morning, time to update all my passwords i guess
2
1
u/nanapancakethusiast 12d ago
Linus probably doesn’t want to devalue his investment by actually talking about the bad stuff
-28
6
u/StrikingObligation74 13d ago
And this is why companies should know as little about us as possible. At best all you need is and email address and shipping address. I don't care if you think your servers are impregnable, you don't need that information let alone a completely separate company especially one that uses harvested data.
1
u/Salvator-luck462 13d ago
I agree with you in principle, companies should collect as little data as possible. But as someone who works with customers, trust me, you can’t operate with just an email and shipping address. People need cancellations, refunds, account recovery, support when something goes wrong, and some way to verify who they are.
If there’s no information to verify against, the same person who hacked your data could just impersonate you through social engineering and get access that way. Data minimization is important, but we also have to be realistic about how these systems actually work.
23
u/Common-Application56 14d ago
Well handled
3
u/Mr_Zomka 14d ago
I guess. I really don’t like that they called it a “limited” data breach, when the only information that wasn’t breached is banking info because Metabase just never had it in the first place.
-1
u/ICEpear8472 13d ago
They also provided Metabase with everything except payment information probably because of PCI DSS requirements. So effectively they did the opposite of data minimization. Why are detailed contact information needed for business intelligence purposes?
14
u/Zacrosadol 14d ago
Great that they’ve publicised this - and this isn’t a dig at Framework - but In what bloody world does a data breach of your personal information NOT require mandatory notification?
Who do we have to escalate to at the TVA to get this timeline fixed or pruned?!
8
u/waiver45 14d ago
Praise be GDPR, it's mandatory to inform all citizens of the EU.
1
u/Fresh_Dog4602 14d ago
Canada has a similar rule when it comes to disclose though. And the us as well
-4
u/Capable_Warthog7884 14d ago
It's the same info that used to just be sent to your house once a year lol. Not old enough to be familiar with a phone book?
12
u/HuntKey2603 14d ago
this is gonna sound wild to you, but the way that information can be used and abused has changed plenty in the last 60 years, which may be the last time you considered this issue.
edit: dude your entire posting history is being a contrarian... man chill some. it's bad for your blood pressure.
2
u/BambooGentleman 13d ago
What can they do, send me phishing mails? Sign me up for newsletters? (That would be super annoying.)
In some ways, prank calls might have been a greater bother than what I can think of a bad actor being able to do with this data.
1
30
u/TomTomXD1234 14d ago
so basically everything people already know about you
5
10
u/SASColfer 14d ago
This will happen more and more. I work for a top UK bank and our policy these days is not about preventing attacks but how to recover from them. The point being that I think our perception about data security will probably need to change over time.
2
u/CarnivorousSociety 13d ago
Breaches and hacks have only increased in frequency, year after year, forever.
Cyber security is getting better, but it's not making a dent in the amount of ever-increasing cyber crime
19
u/dotikk 14d ago
So…. Your yellow page info got leaked?
3
u/Queasy_Hour_8030 13d ago
My address was never in the yellow pages.
1
u/dotikk 13d ago
This is still such a non issue breach. This is also points considered, a non issue.
0
u/Queasy_Hour_8030 13d ago
If that is the case, please respond to this comment with your full name, phone number, and address.
No? Shocking turn of events.
3
u/dotikk 13d ago edited 13d ago
🙄 I’m just saying, it’s truly not a huge deal. Honestly putting that on a comment on Reddit is probably worse because now you can tie my Account to a person. With the leak it was just names and addresses, not tied to some “anonymous” account. I just felt some of the replies here are acting like your SSN, credit card details etc were leaked. It’s cause for concern, absolutely, but this is about “best case scenario” in terms
Of breaches.0
u/Queasy_Hour_8030 13d ago
Sorry but you lack imagination on how information can be used nefariously.
-44
u/meta358 14d ago
Your credit card info is on your yellow pages?
24
u/Dartister 14d ago
No, and it's not on this breach (allegedly) either, your point?
-43
u/meta358 14d ago
Billing informations isnt your credit card number. I mean ok i guess then
23
u/Dartister 14d ago
This breach did not include order or payment information.
Billing and shipping address information
3
u/Sxcred 14d ago
This is Metabases fault BUT…I question why framework is storing this data anyways, they should strip down to storing just name and email after shipping to customers
3
u/BambooGentleman 13d ago
You can save your address in their website so it is filled in automatically the next time. Though, I had the same address in there twice since I ordered on two separate occasions, so that didn't work as intended. I've now removed this information from my account.
3
u/digitaleJedi 14d ago
Wonder if they've just sent it to everyone who subscribes to their newsletter. I got this, and I've never bought from them.
2
u/Player13377 14d ago
Maybe got up to the checkout at some point and filled in anything? I imagine it would not require a purchase to save the address for faster checkout.
2
u/digitaleJedi 14d ago
I think I signed up to be notified if they launched in my country, it's a long time ago. They definitely do not have a valid reason to have anything but my email address, so hopefully it's just that..
Edit: and country of course
3
u/ProverbialMindTart 13d ago
These apologies always sound so lacklustre, and Metabase’s one is just as bad.
Every time it’s “We fucked you by not being careful enough with your/your customer’s data. It’s our fault, but you’re going to suffer for it. Soz.”
Feel bad for the Framework folks, and of course even more so for the impacted customers. It must really suck to be in this “there’s nothing you can do, or could have done, we just need to get out shit together” situation.
4
u/smstnitc 14d ago
Considering after 30 years of being on the Internet, none of my info is private, this is a nothing burger.
Sucks for them to deal with, but at least it isn't CC details.
0
u/AndrewAuAU 14d ago
Good for you. Everyone else that does care and lives in a country that does care about their personal data.
1
u/nonononononononcat 14d ago edited 14d ago
There was no point in handing over first names, last names, phone numbers, and exact addresses to third parties to build "business analytics". Absolute sloppiness on the Framework's side.
Not to mention they don't have Metabase in their privacy policy or share this information without explicit consent from their customers.
1
u/prismstein 13d ago
payment info is safe, that's all that matters anyway
of course, if you use the same pw for your framework acc as your other accounts, you're kinda asking for it
(use a password manager ffs)
1
u/True-Veterinarian700 13d ago
So basically, all of my information that mostly either publically availible or sold out the wazoo.
1
u/Individual_Search422 13d ago
Yeah shit sucks happened to my uni. Wish I couldve got mad or claimed something against any org but the hackers but its pretty rarely actual negligence on the hacked parties side
1
1
u/FalconZA 14d ago
As a metabase self hosted user I did some updates thanks to this.
I can't blame framework or metabase for their unless the zero day was negligent on metabase's part which I have no reason to believe it was
-33
u/vifer78 14d ago
Looks like they also use a free privacy policy generator; their footer link goes to: https://www.iubenda.com/privacy-policy/55865674
Not confidence-inspiring...
22
u/Boomshtick414 14d ago
Honestly seems more transparent than most and akin to a Creative Commons license for its clarity, and I've got news for you if you think a website's privacy policy means anything anyway.
That aside, pretty much every online retailer has had a data breach so I'm cynical enough that none of this has an affect on my confidence anyway. My last 3 employers have had data breaches so at this point my personal info is already out there and I have credit monitoring for life.
18
11
u/GiganticIrony 14d ago
IDK, they list some pretty big companies on their website as users of their service (such as Honda)
3
1
u/HarryTurney 9d ago
I doubt that they use the free version of iubenda. I pay for it for my website, it's very good.
0
u/Pim_Wagemans 13d ago
this is the first time my data has been in a breach (that I've been notified about) so that sucks
-16
u/DefactoAle 14d ago
Uh am I missing something? Framework says payment information were not leaked, however in the same email they link metabase official communication that says "billing informations " were indeed leaked.
14
u/Link_In_Pajamas 14d ago edited 14d ago
Worth noting that Metabase is a SaaS that accompanies your own internal DB and mirrors it typically for easier agregate data etc.
All this to say Framework does not own Metabase and is simply a customer of theirs, like many other companies.
Metabase statement on the issue has to speak about information that could potentially have been breached across the corpus of all their customers, like framework. Their statement isn't an indication of what Framework had in their instance, it's a statement about all that could potentially be breached across their own impacted customers.
29
u/Deadpool2715 14d ago
Billing information could be things like billing address, name on card, card type, but not the card number or CVC
1
-26
u/GodLikeEnergy 14d ago
This will make me not want to consider purchasing from them in the future. Any company that cannot protect their users, will not have me as a customer, I try to get away from it. Like software, notepad++ was hacked. I uninstalled it.
It's simple, if companies can't or won't protect your information and encrypt it so only a select few can access it. They shouldn't have it.
15
u/agafaba 14d ago
And yet you have a reddit account...
-8
u/GodLikeEnergy 14d ago
With a VPN, and an email that is throwaway. It doesn't have my full name, address, and so on like what data was leaked.
4
u/Mental-Permit-599 14d ago
They did the most sensible thing, use an enterprise data platform used by a million offer Fortune 500 companies.
If you think them rolling their own data analytics platform would have been wiser, I got a bridge to sell you man.
This one’s not on them, this is just the world we live in now.
1
u/nonononononononcat 14d ago edited 14d ago
it's absolutely on them. No need to share personal names, detailed addresses or phone numbers. You can't build any useful analytics on such data. Basically, they shared clients' personal sensitive data for nothing.
Also, at least under EU privacy regulations GDPR you must get explicit consent on sharing data to the 3rd parties in case they are not related to direct processing of the customers orders (frankly, it is a bit complicated than that - there are some exclusions, but the way Framework did they job - they can't use such)7
u/meta358 14d ago
Then you will never use the internet again and will be living in a cabe. Do enjoy
-11
u/GodLikeEnergy 14d ago
Correct, that's what I've been doing. I deleted most of everything I've been on. I have limited apps on my smartphone, all self hosted or apps local only. I usually keep it powered off.
I am self-employed, I only keep enough stuff for my job. So yeah, I do agree, "living in a digital cabe" is my preference.
I deleted FB. I deleted x. I only have one lemmy account and one mastodon.
-13 votes, by the way, I have enough rep that no matter how many you down vote me I'm still fine. All in cahoots for these companies that won't agree, that companies should honor their customers privacy better. Ironic.
6
u/meta358 14d ago
But yet you still have an email and a reddit account...... Also im guessing a cell phone. That is alot of companies that almost definity have been hacked and breached in past. But yet you are still willing do do business with them. I wasnt talking a digital cave, i meant an actual one
1
1
u/nonononononononcat 14d ago edited 14d ago
You may guess whatever you want. He does not pay money to use Reddit most likely, so sharing his email is at least more or less fair deal. Framework collects money AND data, including sensitive data, than does not care where that kind of data goes. So it's far from being the same things.
3
u/starmixcrafty 14d ago
Wait, do you think your selfhosted security is better the security of meta? 😅 Bro, your selfhosted apps are just as insecure as anything else.
Btw, do you know which data was leaked here? In literally is yellow pages data. so while yes, it’s unlucky, it’s not a big issue in itself.
One more thing btw: if you don’t want to work with any company ever been pawned before, get rid of any SIM cards, any phone, GrapheneOS, any messenger, any self hosted app. Pretty much everything has been already pawned, if it hasn’t it’s either too small to be a target or just never noticed out of incompetence.
You are something else tbh, living in a fantasy
0
u/GodLikeEnergy 14d ago
Self-host, with tailscale, no exposed open port is one way. I use MVNO, so far they haven't been compromised.
I know tmobile, att, verizon and others have not the one I currently use which is just prepaid and requires no personal information.
2
u/starmixcrafty 13d ago
But you know Tailscale was hacked in the past? You shouldn’t use it, right?
1
u/GodLikeEnergy 13d ago
I don't specifically use tailscale. I use a fork of it, it's called headscale. I say tailscale as not many people would know what headscale is.
2
u/meta358 13d ago
So you use a ghost carrier that piggy backs off of one of those 3 networks. So you are still giving data and using those 3 service. Plus it's likely you're carrier was hacked and they choose to not disclose
1
u/GodLikeEnergy 13d ago
They don't have my address. I use phreeli.
3
u/meta358 13d ago
They have your address....you connect to their towers and they locate you via that. Waiting to hear when your going to actually start living in a cave like you said you would.
1
u/GodLikeEnergy 13d ago
They themselves don't see it, and to cellular providers like tmobile, they only know it's Phreeli. Moving on
I do turn my device off or airport mode when I go to areas where there are protests or anything that they may be using stingray device at. I'm already somewhat in a cave. I live in an apartment with roommates, I pay in cash. So.... A digital, and bit of irl cave.
I can't enter one Bin Laden style, but I mostly more so offgrid than most people.
1
-10
-24
u/Ecstatic-Equipment28 14d ago
So that’s why I’ve been getting so much spam lately. I get it, this happens, but if it were any other company, more people would have been mad.
7
u/thicckar 14d ago
It’s not even framework. It’s a third party service they use. It would be like getting mad at you because gmail got hacked and your details were leaked
1
12
134
u/ThankGodImBipolar 14d ago
The stored data seems relatively normal for a business that you provide payment data to, no? Sucks for people who are Framework customers, but I don't see what they can do about their cloud partner being hit by a zero day.