Framework Discloses Data Breach Via Metabase 0-Day

Framework Discloses Data Breach Via Metabase 0-Day

Framework says a Metabase data breach leaked customer names, emails, phone numbers, and addresses. Here’s what happened, why the details matter, and how you can protect yourself from phishing attempts.

What Happened?

According to Framework’s notice to affected customers, attackers accessed customer information through Metabase, a business intelligence platform used by the company.

Metabase discovered the attack on August 3, 2026. The attacker used a zero-day vulnerability in Metabase Cloud versions 1.58 and above. A zero-day is a software weakness that attackers can use before the developer knows about it or has a fix ready.

Metabase then blocked the affected access points, patched the vulnerability, contacted law enforcement, and hired an outside forensic firm to investigate.

On August 6, Metabase notified Framework that its system had been accessed. Framework reviewed the logs and confirmed that customer information had been reached.

Framework community members praised the company for responding quickly. One member said customers were notified about six hours after Framework received Metabase’s warning.

Even without passwords or payment card details, leaked names, emails, phone numbers, and addresses can help criminals make phishing messages look more convincing. And this risk is not limited to one breach. Your information may already have appeared in another data breach without you realizing it.

If you are unsure whether your information has been leaked, automatic monitoring can help you spot problems earlier. Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Who Was Affected and What Data Was Leaked?

Framework said affected customers could have had the following information leaked:

  • Full name
  • Email address
  • Login IP addresses
  • Billing and shipping address information
  • Country
  • City
  • State
  • ZIP code
  • Phone number
  • Company information

For Framework for Business customers, the company was also investigating several additional data fields. These included VAT, EIN, phone, and billing email information.

Framework said no order information or payment information was accessed.

The company has not publicly said how many customers were affected.

How the Metabase Zero-Day Led to the Breach

The attack did not begin inside Framework’s own store or payment system.

Instead, criminals accessed its Metabase environment through a previously unknown software vulnerability.

Metabase is a business intelligence tool. Companies use tools like this to analyze business information and create reports or dashboards.

Because Framework had customer information available through Metabase, the attacker was able to reach some of that data.

After receiving the warning, Framework rotated credentials for databases connected to Metabase. It also checked for unexpected administrator access.

Framework said it found no changes to administrator access and no access to systems outside Metabase.

The company is now reviewing how much information it shares with business intelligence platforms. It plans to limit access to only the data needed for analysis.

Check if your data is safe from scammers

Futureproof scans your data for leaks and shows exactly how to close security gaps — before scammers find them first.

Check my safety