-
44 votes
-
Danish government confirms its Central Person Register was hacked – data breach affects eight million citizens and includes names, addresses, and social security numbers
24 votes -
Framework customer info has been breached
Just got this email from Framework: Dear Valued Framework Customer, We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an...
Just got this email from Framework:
Dear Valued Framework Customer,
We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an attacker accessing customer names, email addresses, phone numbers, and addresses. Your information was in the database that was accessed in this breach. This breach did not include order or payment information.
We have full details on the incident below. We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors.
We are also in the process of notifying the regulatory authorities in each region where relevant regulations exist. Note that while regulations in most regions do not require notification for breaches of names, email addresses, phone numbers, and addresses, we are sending this email to you regardless to ensure you have visibility and can take any actions needed.
What happened?
On August 6th, 2026 at 9am Pacific Time, Metabase notified us of a breach of their systems with the following email message:
On Monday, August 3, we discovered that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above. We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability. We notified law enforcement, and we have engaged with a third party forensics firm to conduct an independent investigation.
Your instance of Metabase was vulnerable to this 0-day. Therefore, to protect your company, we recommend you:
Rotate the credentials for every database connected to your instance; and
Review the admin accounts on your instance and remove anything you don't recognize.
We also discovered that the attacker was able to gain access to your instance. We created a report on the actions we believe the attacker took on your instance, which includes log files, and which you can get from the Metabase Store at [removed url].
(If you do not have access to the Metabase Store, are having issues accessing the report, or do not want to click on a link in an unexpected email, you can log into your instance directly and reach us at Help > Get help in the grid menu in the upper right hand corner. We'll confirm this message is from us and email you the report.)
This report is based on our own application logs. We did not query or read the data in your connected databases.
Depending on the jurisdictions in which you operate and kinds of data your instance connects to, you may have notification obligations under applicable laws. If you have concerns in this regard, we recommend you assess potential notification obligations with your company’s legal or compliance experts.
We regret any inconvenience this incident may cause you, and we are here to support you. If you have questions, please reply to this email or email us at [removed email address], and we'll get back to you as quickly as we can.
Sameer Al-Sakran
Founder and CEO
Metabase
We immediately investigated the logs Metabase provided to us and confirmed that our database instance was accessed by the attacker. We confirmed that the following information was accessed:
- Full name
- Email address
- Login IPs
- Billing and shipping address information
- Country
- Address
- City
- State
- Zip code
- Phone number
- Company
For Framework for Business customers, we are investigating whether the following information may additionally have been accessed:
- Company
- Phone
- VAT
- EIN
- Billing Email
- No other personally identifiable information, order information, or payment information was accessed.
Note that Metabase has additionally flagged:
Important: This is a preliminary update based on our current knowledge.
We are working with a third-party forensic investigation firm to understand the full nature and scope of the event.
We are providing you this interim update in advance of completing our investigation to allow you to better understand any potential impact and secure your data.
Our investigation is ongoing and the information shared now is preliminary.
Please look at the application logs as well as the queries executed that are provided as separate files in the zip file for detailed activity and a potential timeline.
We’re providing you notice of the breach in the meantime to ensure you have the earliest possible visibility. In the event Metabase notifies us of additional information that impacts you, we will send a follow-up email.
What was done to resolve the issue?
After we were notified of the breach by Metabase, we rotated credentials on all databases associated with our Metabase instance and confirmed that there were no changes in admin access or access to systems outside of Metabase.
What steps have you taken to ensure this doesn’t happen in the future?
We are evaluating the breadth and depth of data shared with business intelligence platforms, and scoping down their access to only the columns required for analysis.
Nirav Patel and the Framework Team
53 votes -
52% of Americans think their personal data will be breached. They're probably right.
25 votes -
GitHub confirms breach of 3,800 repos via malicious VSCode extension
27 votes -
A faceless hacker stole my therapy notes – Meri-Tuuli was one of 33,000 Vastaamo patients held to ransom in October 2020 by a Finnish hacker
16 votes -
PornHub extorted after hackers steal Premium member activity data
33 votes -
Troy Hunt: Two billion email addresses were exposed, and we indexed them all in Have I Been Pwned
18 votes -
Discord says 70,000 users may have had their government IDs leaked in breach
49 votes -
The viral 'Tea' app just had a second data breach, and it's even worse
50 votes -
Mysterious database of 184 million records exposes vast array of login credentials
25 votes -
Coinbase says cost of recent cyber-attack could reach $400m
17 votes -
Twilio denies breach following leak of alleged Steam 2FA codes
18 votes -
More US telcos confirm Salt Typhoon breaches as White House weighs in
20 votes -
Misogynist hacker who threatened the wrong woman (hacker) and found out
23 votes -
Game Freak acknowledges massive Pokémon data breach, as employee info appears online
16 votes -
Darknet Diaries, Ep 148: Dubsnatch
6 votes -
AT&T says criminals stole phone records of ‘nearly all’ US customers in new data breach
26 votes -
Bruce Schneier on the US Consumer Financial Protection Bureau's proposed data rules
7 votes -
Ten years later, new clues in the Target breach
24 votes -
After hack, personally identifiable information records of a large percentage of citizens of India for sale on the dark web. The hack includes biometric data.
22 votes -
Prosecutors in Finland have charged a hacker accused of the theft of tens of thousands of records from psychotherapy patients
9 votes -
US building automation giant Johnson Controls hit by ransomware attack
8 votes -
Wyze security breach: Why we’re pulling our recommendation of Wyze security cameras
27 votes -
Experts link LastPass security breach to a string of crypto heists
48 votes -
Mom’s Meals discloses data breach impacting 1.2 million people
17 votes -
A data breach at Christie’s revealed exact GPS coordinates of collectors’ artworks
25 votes -
Using computers more freely and safely
8 votes -
LastPass recent security incident
7 votes -
Rockstar Games issue message regarding recent leak
7 votes -
Plex breach exposes usernames, emails, and encrypted passwords
12 votes -
Chipmaker Nvidia investigating potential cyberattack
6 votes -
Company that routes SMS for all major US carriers was hacked for five years
27 votes -
LinkedIn breach reportedly exposes data of 92% of users, including inferred salaries
13 votes -
780GB of data, tools, and source code were stolen from EA by purchasing a stolen cookie to get access to the company's Slack and social-engineering an IT Support employee
21 votes -
Huge Eufy privacy breach shows live and recorded cam feeds to strangers
5 votes -
Three years later: Did the GDPR actually work?
7 votes -
Hackers try to contaminate Florida town's water supply through computer breach
15 votes -
Inside the Cit0Day breach collection (now loaded into Have I Been Pwned and Pwned Passwords)
9 votes -
Why the extortion of Vastaamo matters far beyond Finland – and how cyber pros are responding
4 votes -
Finland's interior minister summoned an emergency meeting after patient records at a private Finnish psychotherapy center were accessed by hackers
5 votes -
Former Chief Security Officer for Uber charged with obstruction of justice for attempted cover-up of 2016 hack that compromised data from millions of users and drivers
9 votes -
Disappearance of multiple Saudi Arabian dissidents tied to Twitter data accessed in 2015 by employees allegedly spying for the government
7 votes -
Coronavirus: Iran cover-up of deaths revealed by data leak
13 votes -
Dating apps exposed 845GB of explicit photos, chats, and more
11 votes -
Secret-sharing app Whisper left hundreds of millions of users’ intimate messages, locations, and other data exposed publicly on the web
9 votes -
Have I Been Pwned is no longer being sold, and Troy Hunt will continue running it independently
29 votes -
The story of how Saudia Arabia influenced two well-liked Twitter employees to access thousands of users' private information and pass it to the Saudi Royal Family
10 votes -
Four Chinese military personnel charged for Equifax hack
10 votes -
Breach in payment-processing systems at Wawa convenience stores may have compromised over thirty million cards
5 votes