Framework discloses data breach via Metabase 0-day

Framework moved fast after a customer data scare, but commenters are raging at the data hoard

TLDR: Framework won praise for warning customers quickly after a third-party tool exposed personal details. But commenters say the bigger scandal is that companies keep trusting cloud services with too much customer data in the first place.

Framework may have earned rare internet applause for speed, but the comment section still turned into a full-blown trust issues convention. The company told customers within hours after learning that outside reporting tool Metabase had been breached, and people were genuinely stunned. In a world where companies often go quiet for weeks or months, commenters called Framework’s response almost suspiciously competent. That part got praise. The rest? Total drama.

A big chunk of the community zeroed in on the same villain: analytics and customer-tracking tools. One commenter basically summed up the mood as, “here we go again,” pointing out that these platforms keep becoming the back door to personal customer details. Another dropped the most deliciously smug reaction of the thread, saying their old boss who moved everything back in-house is probably “laughing now.” Ouch.

Then came the privacy revolt. One customer was furious that so much personal information was sitting around at all — name, address, phone number, even internet address history — and said they’d already requested full deletion under European and California privacy laws. Others went even harder, arguing companies already know these easy cloud services are risky and choose them anyway because they’re convenient and help sales move faster. Translation: people aren’t just mad about the breach, they’re mad about the whole modern business playbook.

So yes, Framework got credit for honesty. But the community’s hotter take was brutal: fast disclosure is great, yet maybe stop stockpiling so much customer data in the first place. That’s the real fight now.

Key Points

  • Framework said a Metabase Cloud 0-day breach resulted in unauthorized access to customer data in Framework’s Metabase instance.
  • Metabase said the attack used an unknown vulnerability affecting versions 1.58 and above and was discovered on August 3, 2026.
  • Framework said accessed data included names, email addresses, login IPs, and billing and shipping address details, including phone numbers and company fields.
  • Framework said no order information, payment information, or other personally identifiable information was accessed.
  • After notification, Framework rotated credentials for all associated databases and said it found no admin changes or access to systems outside Metabase.

Hottest takes

"Metabase again?? Last 0day was catastrophic." — pelagicAustral
"There's no reason Framework needed to be storing this much PII about me all this time" — hellcow
"virtually every SaaS sucks ass at security because it slows down sales" — lrvick
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.