Computer maker Framework has notified its entire customer base of a data breach that exposed personal information. Hackers accessed names, email addresses, phone numbers, and physical addresses.
Framework disclosed the breach to all affected customers, confirming that attackers gained access to customer personal data stored in the company's systems. The exposed information includes names, email addresses, phone numbers, and physical addresses.
The company has not yet disclosed additional details about the breach timeline, the number of affected customers, or the identity of the threat actors responsible. Framework has not announced what steps led to the discovery of the breach or what security measures are being implemented to prevent future incidents.
Data breaches involving physical addresses and contact information can expose customers to targeted phishing attacks, identity theft, and unwanted solicitation. Companies handling customer data are typically required to notify affected individuals within specific timeframes under data protection regulations in various jurisdictions.
Framework has not released a formal statement detailing its incident response plan or whether it is offering affected customers credit monitoring services or other protective measures.
Cyberattacks against hedge funds and private equity firms have been attributed to UNC6671, an extortion group connected to the BlackFile threat actors. The campaign represents an escalating threat to the financial sector.
A Go-based malware distributed through ClickFix attacks is targeting macOS users to steal cryptocurrency, passwords, and Apple Keychain data. The infostealer campaign combines social engineering with credential harvesting.
A former NSA official has warned against connecting water infrastructure controllers to the internet following suspected Iranian cyberattacks on U.S. water systems.
Security researchers scanning Polish government websites discovered critical vulnerabilities that could expose courts, hospitals, and airports to cyberattacks. The vulnerabilities stem from common software used to manage and display web content.