{"id":328253,"date":"2026-08-07T09:00:55","date_gmt":"2026-08-07T07:00:55","guid":{"rendered":"https:\/\/borncity.com\/blog\/?p=328253"},"modified":"2026-08-07T18:42:25","modified_gmt":"2026-08-07T16:42:25","slug":"datenschutzvorfall-bei-laptop-hersteller-framework-august-2026","status":"publish","type":"post","link":"https:\/\/borncity.com\/blog\/2026\/08\/07\/datenschutzvorfall-bei-laptop-hersteller-framework-august-2026\/","title":{"rendered":"Datenschutzvorfall bei Laptop-Hersteller Framework (August 2026)"},"content":{"rendered":"<p><img decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" title=\"Sicherheit (Pexels, allgemeine Nutzung)\" src=\"https:\/\/borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Sicherheit_klein.jpg\" alt=\"Sicherheit (Pexels, allgemeine Nutzung)\" width=\"200\" align=\"left\" \/>Unsch\u00f6ne Geschichte, die Kunden des Notebook-Herstellers Framework getroffen hat. Dem Anbieter wurde seine Cloud-Instanz mit einer Datenbank, die f\u00fcr Business-Intelligence verwendet wurde, beim Anbieter Metabase gehackt. Infolge dessen gelang es einem Angreifer Kundendaten abzuziehen. Framework hat betroffene Kunden informiert, wie ich \u00fcber einen betroffenen Leser erfahren habe.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg09.met.vgwort.de\/na\/6ebf86d451ea4f74978dbb3e2c491a93\" alt=\"\" width=\"1\" height=\"1\" \/>Blog-Leser Lars Henrick K. hat mich heute morgen per E-Mail kontaktiert und schrieb: \"Unerfreuliche Nachrichten, aus dem Urlaub. Aber jetzt scheint es auch Framework erwischt zu haben.\"<\/p>\n<h2>Wer ist Framework?<\/h2>\n<p>Framework (Website: frame.work) ist ein US-amerikanischer Computerhersteller, der f\u00fcr seine extrem modularen und leicht reparierbaren Laptops bekannt ist. Das Unternehmen wurde von Nirav Patel gegr\u00fcndet, um Elektroschrott zu reduzieren und das Recht auf Reparatur (Right to Repair) zu st\u00e4rken. Bekannt d\u00fcrfte das Unternehmen durch seine Framework-Laptops sein.<\/p>\n<h2>Es gab einen Cybervorfall<\/h2>\n<p>In einer E-Mail, die ich von oben erw\u00e4hnten Blog-Leser erhalten habe, informiert Framework \u00fcber einen Datenversto\u00df. Konkret habe es einen\u00a0Datenversto\u00df gegeben, der beim verwendeten Business-Intelligence-Datenbankanbieter Metabase stattgefunden habe, schreibt Framework.<\/p>\n<h3>Metabase Cloud-Instanz gehackt<\/h3>\n<p>Ich versuche es mal etwas aufzudr\u00f6seln. Metabase ist eine weit verbreitete, nutzerfreundliche Open-Source-Software f\u00fcr Business Intelligence (BI) und Datenvisualisierung. Sie erm\u00f6glicht es Unternehmen und Teams, Daten aus verschiedenen Datenbanken abzufragen, zu analysieren und in interaktiven Dashboards darzustellen. Das Ganze wird meiner Lesart nach bei Metabase in einer Cloud gehostet.<\/p>\n<p>Im Klartext besagt die obige Information zum \"Metabase Datenversto\u00df\": Denen wurde die Cloud-Instanz der Metabase-Datenbank, in der auch die Kundenbeziehungen und -daten abgespeichert waren gehackt.\u00a0Durch den Angriff auf Metabase erlangte ein Angreifer Zugriff auf Kundennamen, E-Mail-Adressen, Telefonnummern und Anschriften, hei\u00dft es in der Mitteilung.<\/p>\n<h3>Metabase wurde am 3. August 2026 gehackt<\/h3>\n<p>Am 6. August 2026 wurde Framework von Metabase per E-Mail \u00fcber einen Sicherheitsvorfall informiert, der bereits am dem 3. August 2026 passiert ist. Metabase stellte fest, dass die Metabase Cloud von einer Person angegriffen wurde, die eine unbekannte (\"0-Day\") Sicherheitsl\u00fccke in den Versionen 1.58 und h\u00f6her ausnutzte. Die IT habe die f\u00fcr den Angriff verwendeten Endpunkte umgehend gesperrt und anschlie\u00dfend die Sicherheitsl\u00fccke schnell identifiziert und behoben, hei\u00dft es.<\/p>\n<h2>Strafverfolger und Forensiker informiert<\/h2>\n<p>Framework ein externes Forensikunternehmen mit der Durchf\u00fchrung einer unabh\u00e4ngigen Untersuchung beauftragt. Das Unternehmen bedauert\u00a0diesen Datenversto\u00df und ist nun dabei, seine Vorgehensweise bei der Datenspeicherung bei externen Datenbankanbietern zu \u00fcberpr\u00fcfen und zu verbessern.<\/p>\n<p>Weiterhin gibt man an, die Strafverfolgungsbeh\u00f6rden eingeschaltet zu haben und die Aufsichtsbeh\u00f6rden in allen Regionen zu benachrichtigen, in denen entsprechende Vorschriften gelten.<\/p>\n<hr \/>\n<p>Nachfolgend findet sich noch die Original-Nachricht<\/p>\n<blockquote><p>Dear Valued Framework Customer,<\/p>\n<p>We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an attacker accessing customer names, email addresses, phone numbers, and addresses. Your information was in the database that was accessed in this breach. This breach did not include order or payment information.<\/p>\n<p>We have full details on the incident below. We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors.<\/p>\n<p>We are also in the process of notifying the regulatory authorities in each region where relevant regulations exist. Note that while regulations in most regions do not require notification for breaches of names, email addresses, phone numbers, and addresses, we are sending this email to you regardless to ensure you have visibility and can take any actions needed.<\/p>\n<p>What happened?<\/p>\n<p>On August 6th, 2026 at 9am Pacific Time, Metabase notified us of a breach of their systems with the following email message:<\/p>\n<p>On Monday, August 3, we discovered that Metabase Cloud was attacked by someone utilizing an unknown (\"0-day\") security vulnerability in versions 1.58 and above. We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability. We notified law enforcement, and we have engaged with a third party forensics firm to conduct an independent investigation.<\/p>\n<p>Your instance of Metabase was vulnerable to this 0-day. Therefore, to protect your company, we recommend you:<\/p>\n<p>Rotate the credentials for every database connected to your instance; and<\/p>\n<p>Review the admin accounts on your instance and remove anything you don't recognize.<\/p>\n<p>We also discovered that the attacker was able to gain access to your instance. We created a report on the actions we believe the attacker took on your instance, which includes log files, and which you can get from the Metabase Store at [removed url].<\/p>\n<p>(If you do not have access to the Metabase Store, are having issues accessing the report, or do not want to click on a link in an unexpected email, you can log into your instance directly and reach us at Help &gt; Get help in the grid menu in the upper right hand corner. We'll confirm this message is from us and email you the report.)<\/p>\n<p>This report is based on our own application logs. We did not query or read the data in your connected databases.<\/p>\n<p>Depending on the jurisdictions in which you operate and kinds of data your instance connects to, you may have notification obligations under applicable laws. If you have concerns in this regard, we recommend you assess potential notification obligations with your company's legal or compliance experts.<\/p>\n<p>We regret any inconvenience this incident may cause you, and we are here to support you. If you have questions, please reply to this email or email us at [removed email address], and we'll get back to you as quickly as we can.<\/p>\n<p>Sameer Al-Sakran<\/p>\n<p>Founder and CEO<\/p>\n<p>Metabase<\/p>\n<p>We immediately investigated the logs Metabase provided to us and confirmed that our database instance was accessed by the attacker. We confirmed that the following information was accessed:<\/p>\n<p>Full name<br \/>\nEmail address<br \/>\nLogin IPs<br \/>\nBilling and shipping address information<br \/>\nCountry<br \/>\nAddress<br \/>\nCity<br \/>\nState<br \/>\nZip code<br \/>\nPhone number<br \/>\nCompany<\/p>\n<p>For Framework for Business customers, we are investigating whether the following information may additionally have been accessed:<\/p>\n<p>Company<br \/>\nPhone<br \/>\nVAT<br \/>\nEIN<br \/>\nBilling Email<\/p>\n<p>No other personally identifiable information, order information, or payment information was accessed.<\/p>\n<p>Note that Metabase has additionally flagged:<\/p>\n<p>Important: This is a preliminary update based on our current knowledge.<\/p>\n<p>We are working with a third-party forensic investigation firm to understand the full nature and scope of the event.<\/p>\n<p>We are providing you this interim update in advance of completing our investigation to allow you to better understand any potential impact and secure your data.<\/p>\n<p>Our investigation is ongoing and the information shared now is preliminary.<\/p>\n<p>Please look at the application logs as well as the queries executed that are provided as separate files in the zip file for detailed activity and a potential timeline.<\/p>\n<p>We're providing you notice of the breach in the meantime to ensure you have the earliest possible visibility. In the event Metabase notifies us of additional information that impacts you, we will send a follow-up email.<\/p>\n<p>What was done to resolve the issue?<\/p>\n<p>After we were notified of the breach by Metabase, we rotated credentials on all databases associated with our Metabase instance and confirmed that there were no changes in admin access or access to systems outside of Metabase.<\/p>\n<p>What steps have you taken to ensure this doesn't happen in the future?<\/p>\n<p>We are evaluating the breadth and depth of data shared with business intelligence platforms, and scoping down their access to only the columns required for analysis.<\/p>\n<p>Nirav Patel and the Framework Team<\/p>\n<p>\u00a9 2026 Framework Computer Inc<\/p>\n<p>447 Sutter St, PMB 135, San Francisco, CA, 94108-4618<\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>Unsch\u00f6ne Geschichte, die Kunden des Notebook-Herstellers Framework getroffen hat. Dem Anbieter wurde seine Cloud-Instanz mit einer Datenbank, die f\u00fcr Business-Intelligence verwendet wurde, beim Anbieter Metabase gehackt. Infolge dessen gelang es einem Angreifer Kundendaten abzuziehen. Framework hat betroffene Kunden informiert, wie &hellip; <a href=\"https:\/\/borncity.com\/blog\/2026\/08\/07\/datenschutzvorfall-bei-laptop-hersteller-framework-august-2026\/\">Weiterlesen <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[426],"tags":[4328],"class_list":["post-328253","post","type-post","status-publish","format-standard","hentry","category-sicherheit","tag-sicherheit"],"_links":{"self":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/328253","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/comments?post=328253"}],"version-history":[{"count":4,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/328253\/revisions"}],"predecessor-version":[{"id":328257,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/328253\/revisions\/328257"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/media?parent=328253"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/categories?post=328253"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/tags?post=328253"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}