Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Laptop Maker Framework Says Customer Data Stolen in Third-Party Breach

Device maker Framework is notifying users that their personal information was stolen in a data breach at its external accounting partner.

Laptop computer maker Framework is notifying users that personal information was stolen in a data breach at its primary external accounting partner.

The California-based company said the incident occurred on Thursday, January 11, and was the result of a phishing attack targeting an employee at Keating Consulting.

According to the notification that Framework sent to the impacted individuals, a copy of which shared by the company with SecurityWeek, the phishing email was received on January 9.

Impersonating the Framework CEO, the attackers requested Keating Consulting’s employee to provide “accounts receivable information pertaining to outstanding balances for Framework purchases.”

The employee responded to the email on January 11, sending the attackers a spreadsheet containing the full names, email addresses, and balance owned related to a subset of open pre-orders and some completed past orders.

Framework was made aware of the incident roughly half an hour after the response email was sent to the attackers and Keating Consulting was informed of the error.

“We identified all impacted customers to enable mass-notification of the breach (this email),” the company said.

Framework said it informed Keating Consulting of the breach and the attack vector, asking them to train employees with access to customer information on phishing and social engineering attacks.

Advertisement. Scroll to continue reading.

“We are also auditing their standard operating procedures around information requests. We are additionally auditing the training and standard operating procedures of all other accounting and finance consultants who currently or previously have had access to customer information,” Framework said.

The company urges users to remain vigilant of any phishing attempts that might impersonate Framework to request payment information or to deliver malicious links.

“If you are ever concerned about the validity of an email received from Framework, please contact Framework Support and we will confirm or deny the authenticity of any correspondence,” the company added.

Framework’s notification did not include details on the number of impacted individuals.

Related: HMG Healthcare Says Data Breach Impacts 40 Facilities

Related: Law Firm Orrick Reveals Extensive Data Breach

Related: Xerox Confirms Data Breach at US Subsidiary

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Gain valuable insights from industry professionals who will help guide you through the intricacies of industrial cybersecurity.

Register

Join us for an in depth exploration of the critical nature of software and vendor supply chain security issues with a focus on understanding how attacks against identity infrastructure come with major cascading effects.

Register

Expert Insights

Related Content

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

CISO Strategy

Okta is blaming the recent hack of its support system on an employee who logged into a personal Google account on a company-managed laptop.

Data Breaches

Sony shares information on the impact of two recent unrelated hacker attacks carried out by known ransomware groups. 

Data Breaches

A group of hackers has leaked Atlassian employee records and floorplans, information that was obtained from third-party workplace platform Envoy.

Data Breaches

Delta Dental of California says over 6.9 million individuals were impacted by a data breach caused by the MOVEit hack.

Data Breaches

KFC and Taco Bell parent company Yum Brands says personal information was compromised in a January 2023 ransomware attack.