I just received an email about a limited data breach, leaking customer information (no billing info though). Do you guys think Framework is handling this well? The email looked very detailed and transparent to me.
The transparency and especially the expediency of notification is greatly appreciated, Iâd say not only by the Framework team but also by Metabase. A 3 day turnaround by Metabase from initial discovery of the incident to notify business partners is impressive. And the Framework team took only 6 HOURS from receiving Metabaseâs notice before internally confirming and notifying their customers!! That is unheard of!! It seems like most companies wait months (at minimum) before notifying customers (if they do at all) because they think any security issue will cause the public to lose trust in them.
These days, itâs not a matter of when you suffer a security incident. Itâs how quickly and transparently you respond to it and notify your customers. In my opinion, the Framework team far exceeded expectations, and I anticipate any updates will be met with the same level of transparency. Other companies need to take note, this is how you handle a security incident.
Credit card info. Need assurance that was not accessed by the hackers.
Their privacy policy states Stripe is used for handling payments, and it was already stated in the email there was no payment information.
Its disappointing another company has chosen to share our personal information with another third party. While at this point I think all of my information has probably already been leaked, I still do not appreciate my data being shared with third party providers. Getting all your personal information leaked because a company you have never heard of or interacted with is getting insanely normalised.
While I appreciate Frameworkâs notice and transparency (moreso than most orgs), I canât say itâs not frustrating to be part of yet another data breach. Maybe we stop sharing so much data with 3rd parties??
I agree. Communication at this level is appreciated. The fact remains that Framework is benefiting from storing our data with a 3rd party for whatever vague analysis they decide to use it for and we bear the consequences of having certain data exposed when it shouldnât be.
From Frameworkâs Notice:
What steps have you taken to ensure this doesnât happen in the future?
We are evaluating the breadth and depth of data shared with business intelligence platforms, and scoping down their access to only the columns required for analysis.
Obviously this is moving in the right direction, but it may reveal that the depth of information previously shared with this platform was excessive to begin with.
Appreciate the transparency, but I do not appreciate the wording of the messaging. Calling this a âlimitedâ breach right in the email subject is quite dishonest when basically all the personally identifiable information is there.
Also the email lists all the personally identifiable information and then it says âno other personally identifiable information has been takenâ. Yeah, thatâs all you had! This feels like a dark pattern of communication. You can do better, framework.
Also, does the business side have to have names, emails of the customers? Also, of course it sucks that only now youâre starting to ask these questionsâŚ
I got the breach notification today. Earlier this week I got an âAction Requiredâ email asking me to update my payment method before my laptop would ship.
I always handle emails like these by ignoring the button and logging in directly at the relevant website (this time Framework). It worked out well, and the email was clearly legitimate.
But Iâd like to flag the pattern. A phishing email built off the breached data would look almost exactly like the one I received: same sender name, same layout, same urgency, same big button to update payment information.
I understand that Framework likely will not strip the link entirely, as it will make the friction of updating payment info too much for some users. But I would suggest that the email primarily asks the customer to log in through the web site and not through a link.
Most Nordic banks dropped payment links from customer emails years ago for this reason. As far as I know this has not been a problem. Given that Framework customers are now a known list of names and addresses, it seems worth revisiting.
Thanks for disclosing the breach quickly. That was handled very well. As I am now awaiting the delivery of my laptop, I will be even more vigilant than normal if I receive an email on import fees etc. that could be a targeted phishing attempt.
Frustrating that it happened. Appreciate being informed so quickly. Not sure about calling it a âlimitedâ data breach, though, considering what was accessed.
Not sure why I got an email about it, I havenât made a purchase but I think I signed up for a waitlist.
I appreciate the response, definitely. In some juristictions (states in the US), itâs not required to disclose âminorâ breaches of public info, and many companies choose not to disclose it.
Iâve been around the block for a few decades and what gave me pause was that it was claimed to be a zero-day exploit, but was immediately patched when the hack was discovered. Those two things donât usually go together and methinks someone dropped the ball on patching.
The way I sometimes interpret âlimitedâ is that they may have gotten all of my info, but perhaps not the entire database of every customer. My idea of âlimitedâ and Frameworkâs idea of âlimitedâ could be two entirely different things.
Iâve been online since the gopher and usenet days and maybe itâs just my weary bones talking, but I live my life with the assumption that regardless of all the precautions Iâve taken, every address, employment record, credit card, checking account, social security number (US), etc. Iâve ever had is out there already. Itâs just that no organized crime syndicate, nor just a two-bit street hustler, is gonna look at a Home Depot card with a $1000 limit and bother with it.
Maybe Framework is handling things well, but now with their addresses out everyone who talked publicly about their recent orders should be considered at risk of targeted physical theft due to the current prices.
For this reason Iâd suggest that the âBatch Xâ topics for recent releases get deleted, but maybe some data gathering already happened there.
i got the email too, kinda worried about my payment information, so i had cancelled the card which was used for payment
Thatâs exactly why you got the email, it was a breach of the systems used to store user information, for their analytics, rather than orders alone.
The frankness and clarity, all out in the open is the only positive part of this bad news delivery. The fact itâs the DB platform that was hit by a zero-day access bug, might be sourced from GenAI/LLM, seems like the near future arriving in a painful way.
I do wonder what felt need there is to keep live vs ageing-off data â I bought my FW13 2 1/2 years ago and maybe Iâll upgrade the screen, but âattackers canât exfiltrate data you donât storeâ applies here.
While I appreciate Frameworkâs quick notice and transparency, I am disappointed that my information was shared with a third party.
Why canât Framework limit the information shared with its partners to only what is absolutely necessary?
Unless this is legally required, I donât see a valid reason for Framework to disclose user data beyond the minimum needed.
Transparency about the incident is appreciated, but protecting user privacy should come first.
Quoting the data breach email:
"What steps have you taken to ensure this doesnât happen in the future?
We are evaluating the breadth and depth of data shared with business intelligence platforms, and scoping down their access to only the columns required for analysis."
Quoting the Privacy Policy:
âWe do not sell, trade, or otherwise transfer to outside parties your personally identifiable information. This does not include trusted third parties who assist us in operating our site, conducting our business, or servicing you, so long as those parties agree to keep this information confidential.â
Put together, it means you shared personally identifiable information that was not needed to a third party (here Metabase), and it was by design because you included it in the Privacy Policy (Metabase is in âconducting your businessâ as a BI platform).
You donât need my full name, email address or complete billing address in Metabase. Why send my private data there in the first place ? I donât care if they âagree to keep this information confidentialâ, good will doesnât prevent data breaches and this was bound to happen sooner or later.
Checking the data shared with Metabase is not enough. What needs to be done is a full data privacy audit to check if your customersâ right to data privacy are respected (including in your project management framework). In other words, are you sending data to platforms that donât need it ? When handling implementation projects, do you have a data analysis to cover these risks ?
I donât want to receive the same email for another of your partners in 6 months. Respecting your customers doesnât stop at the hardware level. It also means ensuring that youâre not setting them up for scams or burglary.
While I appreciate the transparency and responsiveness, Iâm alarmed by the lack of basic data privacy knowledge at Framework. I hope there are sufficient measures taken and Iâm waiting for an official communication about it.
Good to see this thread being created.
I work for a small tech company that feeds PII data into, Iâd guess, 30-40 third parties of this type. This is perfectly legal in the jurisdictions we operate in and, Iâd wager, entirely normal for our sector. The company is struggling to survive, and it needs all sorts of CRM and analytics tools to improve its financial performance. Noting Nicolasâ post, I used to be a bit of a data protection absolutist myself, but I am not sure that approach is realistic.
A practical step we can take: if anyone can find this parcel of data available on the web, it can be sent to Have I Been Pwned?, which is a database of data thefts. This flows into all sorts of data breach tools like Firefox Monitor.
I think Framework actually made it pretty badly here, at least from EU legal privacy regulations (GDPR) perspective:
-
Failure to Anonymize Data:
Framework did not anonymize the dataset, meaning customersâ real names were sent explicitly. Effective business analytics can easily be performed by replacing first and last names with anonymous identifiers or tokens. -
Lack of Data Minimization:
There is absolutely no reason to provide a BI platform with phone numbers or exact apartment numbers. No valuable business metrics rely on this specific data, yet Framework handed it over anyway, violating core data minimization principles. -
Vague & Outdated Privacy Policy:
Their privacy policy has not seen a substantial update since 2020 and completely fails to specify that customer data would be transferred to or processed via Metabase for administrative reporting. -
No Legal Basis or Explicit Consent:
Moving data to an analytics engine is a secondary purpose entirely separate from direct order fulfillment. Under the GDPRâs Purpose Limitation principle, companies cannot legally bundle these activities under blanket terms. Because Framework transferred highly sensitive, unanonymized customer data for corporate reporting, they cannot claim âLegitimate Interest.â They legally required explicit, opt-in user consentâwhich they completely bypassed.
