NHacker Next
  • new
  • past
  • show
  • ask
  • show
  • jobs
  • submit
Framework discloses data breach via Metabase 0-day (community.frame.work)
pelagicAustral 5 hours ago [-]
Metabase again?? Last 0day was catastrophic. My previous employer moved all that infrastructure back to on-prem, I guess he must be laughing now.
whazor 4 hours ago [-]
Even if its on the cloud, should be locked behind your VPN
chocolatkey 4 hours ago [-]
Here's what an email from metabase looks like for those affected:

  On Monday, August 3, we discovered  that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above. We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability. We notified law enforcement, and we have engaged with a third party forensics firm to conduct an independent investigation.

  Your instance of Metabase was vulnerable to this 0-day. Therefore, to protect your company, we recommend you:

  Rotate the credentials for every database connected to your instance; and
   Review the admin accounts on your instance and remove anything you don't recognize.
   We also discovered that the attacker was able to gain access to your instance.  We created a report on the actions we believe the attacker took on your instance, which includes log files, and which you can get from the Metabase Store at https://store.metabase.com.

  (If you do not have access to the Metabase Store, are having issues accessing the report, or do not want to click on a link in an unexpected email, you can log into your instance directly and reach us at Help > Get help in the grid menu in the upper right hand corner. We'll confirm this message is from us and email you the report.)

  This report is based on our own application logs. We did not query or read the data in your connected databases.

  Depending on the jurisdictions in which you operate and kinds of data your instance connects to, you may have notification obligations under applicable laws. If you have concerns in this regard, we recommend you assess potential notification obligations with your company’s legal or compliance experts.

  We regret any inconvenience this incident may cause you, and we are here to support you. If you have questions, please reply to this email or email us at eventresponse@metabase.com, and we'll get back to you as quickly as we can.

  Sameer Al-Sakran
  Founder and CEO
  Metabase

Based on what they shared in terms of logs and summary, the attacker was scanning tables for valuable data. They took the first N rows from various tables in connected DBs, kind of at random it seems. Possibly some kind of regexing. Here's an example timeline:

  | Time | Event |
  | --- | --- |
  | 13:00 | Access gained and authenticated as the administrator account |
  | 13:01 – 13:12 | 54 queries were run through that session |
  | 13:14 | API key was created (key ID `1`) tied to a service account |
  | 13:14 – 13:17 | 19 further queries were run through the API key |
  | 13:17 | API key was deleted |
parable 5 hours ago [-]
While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days.

I don't see a solution to this in the near future. I initially thought up something quite simple: assign every customer a unique ID and use that where possible to reference a customer. That solution, however, renders the analytics and CRM tools nearly useless. There has to be a better way, though, other than haphazardly giving out customer metadata to other vendors. All of that information should stay in-house.

As for why metadata is important: I've said this before, but metadata can't easily be changed. I'd much prefer having my password or credit card number leaked in plaintext since I can change those identifiers trivially. I can't change my name, phone number, or address as easily.

vermon 4 hours ago [-]
Just don't use the cloud version of Metabase. You can self host it and not allow accessing it over the internet.
parable 3 hours ago [-]
Metabase can be self-hosted, but you cannot self-host Salesforce or Mixpanel or many of the other products I'm referring to. In an ideal world, every company would self-host their own instances of all of their products, since that ultimately forces them to be solely responsible for their customers' data. Using the cloud versions of these products shifts the blame from the company itself to the vendor when things go sideways, so it makes more sense for them to do this instead of taking responsibility.
account42 3 hours ago [-]
The solution is obvious: make it illegal for companies to collect and store user data where it is not strictly necessary to fulfill the direct customer needs. Collecting less data and storing it in fewer systems is the most effective way to reduce data breaches and their impact.
cassianoleal 2 hours ago [-]
That is already the case for where I live, and yet I am on that breach, with names, addresses, etc. all leaked. Unfortunately it's not enough to collect "only necessary" if what's necessary is too much in the hands of the attacker.
GoblinSlayer 32 minutes ago [-]
Can't they store that information encrypted? What analytics can be extracted from phone numbers? It's only good to sell on black market.
parable 2 hours ago [-]
This would be nice, and I hope I get to see a future like this, but I moreso meant that I don't see a solution for this issue given the current landscape of things. Ideally, yes, companies wouldn't collect the data and it would be illegal to do so. However, this currently isn't the case, so what can be done that lets all sides win? Something has to give, and I'm certain users will receive the short end of the stick at all times - at least, until there are better laws in place.
yread 2 hours ago [-]
I'm waiting for this for 7 years already: I'm too lazy to setup proper analytics with 800 "legitimate partners" on my website
lrvick 4 hours ago [-]
I say this as a fan of a lot of what Framework is doing.

Lets not pretend we do not all -know- virtually every SaaS sucks ass at security because it slows down sales.

Companies that use these easy button services anyway are knowingly putting PII at risk and any liability should fall on those decision makers.

If you do not have the security and infra staff to take user data in house securely, in highly auditable secure enclaves, then you should not store it at all.

orwin 3 hours ago [-]
I created an account more than two years ago, and never connected to it since. EU rgpd is very clear about data retention delays. I won't report it, but to be clear I am very cross with Framework, when even Chinese companies respect my privacy more.
vladvasiliu 4 hours ago [-]
Let's not pretend we do not all -know- virtually every company looks at security as a cover your ass exercise. The SaaS is able to provide some fort of "certification", so companies are happy to move responsibility to them.

They don't actually care about protecting PII or anything.

account42 3 hours ago [-]
The problem is that all responsibility being moved is who gets to shrug. There need to be nontrivial per customer damages paid for each such incident.
cassianoleal 2 hours ago [-]
I do wonder if this has anything to do with the fact that Framework has taken payment from me 3 days ago, yet my order still shows as "pre-order accepted". No acknowledgement of payment, no shipping ETA.
OroPla 3 hours ago [-]
A bit ironic that I found out about this through this website first despite also having received a mail from Framework about the issue.

Still not sure what to do with this information. It's not like I can change any of the compromised information.

hellcow 5 hours ago [-]
There's no reason Framework needed to be storing this much PII about me all this time including my address, IP addresses and phone number.

I just requested a full delete courtesy of GDPR and CCPA and encourage others to do the same.

OuterVale 5 hours ago [-]
The full email I received:

> Dear Valued Framework Customer,

> We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an attacker accessing customer names, email addresses, phone numbers, and addresses. Your information was in the database that was accessed in this breach. This breach did not include order or payment information.

> We have full details on the incident below. We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors.

> We are also in the process of notifying the regulatory authorities in each region where relevant regulations exist. Note that while regulations in most regions do not require notification for breaches of names, email addresses, phone numbers, and addresses, we are sending this email to you regardless to ensure you have visibility and can take any actions needed.

> What happened?

> On August 6th, 2026 at 9am Pacific Time, Metabase notified us of a breach of their systems with the following email message:

> On Monday, August 3, we discovered that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above. We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability. We notified law enforcement, and we have engaged with a third party forensics firm to conduct an independent investigation.

> Your instance of Metabase was vulnerable to this 0-day. Therefore, to protect your company, we recommend you:

> Rotate the credentials for every database connected to your instance; and

> Review the admin accounts on your instance and remove anything you don't recognize.

> We also discovered that the attacker was able to gain access to your instance. We created a report on the actions we believe the attacker took on your instance, which includes log files, and which you can get from the Metabase Store at [removed url].

> (If you do not have access to the Metabase Store, are having issues accessing the report, or do not want to click on a link in an unexpected email, you can log into your instance directly and reach us at Help > Get help in the grid menu in the upper right hand corner. We'll confirm this message is from us and email you the report.)

> This report is based on our own application logs. We did not query or read the data in your connected databases.

> Depending on the jurisdictions in which you operate and kinds of data your instance connects to, you may have notification obligations under applicable laws. If you have concerns in this regard, we recommend you assess potential notification obligations with your company’s legal or compliance experts.

> We regret any inconvenience this incident may cause you, and we are here to support you. If you have questions, please reply to this email or email us at [removed email address], and we'll get back to you as quickly as we can.

> Sameer Al-Sakran

> Founder and CEO

> Metabase

> We immediately investigated the logs Metabase provided to us and confirmed that our database instance was accessed by the attacker. We confirmed that the following information was accessed:

> - Full name > - Email address > - Login IPs > - Billing and shipping address information > - Country > - Address > - City > - State > - Zip code > - Phone number > - Company

> For Framework for Business customers, we are investigating whether the following information may additionally have been accessed:

> - Company > - Phone > - VAT > - EIN > - Billing Email

> No other personally identifiable information, order information, or payment information was accessed.

> Note that Metabase has additionally flagged:

> Important: This is a preliminary update based on our current knowledge.

> We are working with a third-party forensic investigation firm to understand the full nature and scope of the event.

> We are providing you this interim update in advance of completing our investigation to allow you to better understand any potential impact and secure your data.

> Our investigation is ongoing and the information shared now is preliminary.

> Please look at the application logs as well as the queries executed that are provided as separate files in the zip file for detailed activity and a potential timeline.

> We’re providing you notice of the breach in the meantime to ensure you have the earliest possible visibility. In the event Metabase notifies us of additional information that impacts you, we will send a follow-up email.

> What was done to resolve the issue?

> After we were notified of the breach by Metabase, we rotated credentials on all databases associated with our Metabase instance and confirmed that there were no changes in admin access or access to systems outside of Metabase.

> What steps have you taken to ensure this doesn’t happen in the future?

> We are evaluating the breadth and depth of data shared with business intelligence platforms, and scoping down their access to only the columns required for analysis.

> Nirav Patel and the Framework Team

ishanz 5 hours ago [-]
I got the same email

What’s up with the [removed *]

chias 4 hours ago [-]
The url was to transfer log data from metabase to framework. It is not something that is intended for end user access.
aucisson_masque 2 hours ago [-]
> Maybe Framework is handling things well, but now with their addresses out everyone who talked publicly about their recent orders should be considered at risk of targeted physical theft due to the current prices.

Am I missing something or is this user out of his mind ? This ain't Bitcoin, it's just a damn laptop.

bravetraveler 2 hours ago [-]
Business intelligence, vendor free: I'm done buying from them. Call it harsh, that's fine. That's business, baby.
doublerabbit 2 hours ago [-]
Beacon CRS was also exploited, I wonder if related somehow.
edent 4 hours ago [-]
Perhaps they should have spent a bit more money on security and a bit less on sponsoring "big tent" racists.

https://crimier.github.io/posts/Framework-Omarchy/

philipallstar 4 hours ago [-]
I made it about halfway through that article before giving up. It's all opining on "racists" without highlighting what the actual things were that were said.
account42 3 hours ago [-]
Stop being reasonable we are all gathered here to burn the witch.
OuterVale 3 hours ago [-]
This is a pretty decent run down (and DHH has taken it much further since this post was published): https://jakelazaroff.com/words/dhh-is-way-worse-than-i-thoug...
vaylian 3 hours ago [-]
I agree that sponsoring DHH was a mistake. But I don't see how Framework could have used more money on security to prevent a zeroday in a third party product.
wigger1 3 hours ago [-]
They could have sponsored the political activists driving NixOS instead.
Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
Rendered at 11:15:43 GMT+0000 (UTC) with Wasmer Edge.