框架客户信息在数据泄露事件中被访问

qimuai 发布于 阅读:0 一手编译

框架客户信息在数据泄露事件中被访问

内容来源:https://www.engadget.com/2232708/framework-customer-information-was-accessed-as-part-of-a-data-breach/

内容总结:

框架计算机公司(Framework)近日向其全体客户发出通知,确认其客户的个人信息在一次数据泄露事件中被窃取。该公司以生产可维修、可升级的笔记本电脑而闻名。根据8月6日(周四)晚间发送的邮件,此次泄露涉及客户的姓名、登录IP地址、住址、电话号码及电子邮箱等数据。但邮件明确表示,支付信息并未受到影响。

据悉,此次事件源于该公司业务数据库供应商Metabase遭遇黑客攻击。Metabase在其官网博客中披露,攻击者利用了一个“未知(零日)漏洞”获取了数据,目前该漏洞已被识别并修复。Metabase在邮件中表示,相关调查结果和安全建议仍属于“初步”阶段,并称“我们正在与第三方取证调查机构合作,以全面了解事件的本质和影响范围。”

框架公司表示,在接到泄露通知后,已立即轮换相关登录凭证,并“确认管理权限未发生变更,除Metabase系统外,其他系统未受到入侵”。该公司还表示,正在“审查并改进其在使用外部数据库供应商时的数据存储方法”。

此次数据泄露对框架公司而言可谓雪上加霜。尽管公司今年早些时候发布了令人期待的新产品线,但受全球内存短缺影响,其经营压力远超多数同行。今年1月,框架公司首次宣布提价,3月再度上调价格。在开放新款“框架笔记本电脑Pro”预售不久后,由于组件成本不断攀升,公司被迫削减部分预购订单中的内存容量,并对不愿接受降配的客户提供全额退款。

中文翻译:

框架客户信息因数据泄露被获取,公司称支付详情未受影响。框架(Framework)——这家专营可自行维修和升级电脑的厂商——已通知所有客户,其数据在一次泄露事件中遭到曝光。根据该公司8月6日(周四)晚间发送的一封电子邮件,客户姓名、登录IP地址、地址、电话号码和电子邮箱在黑客入侵该公司业务数据库提供商Metabase时被获取。支付信息未包含在此次泄露中。

框架公司在自己的邮件中附上了Metabase的解释,其中详细说明了该提供商于8月3日发现此次攻击的时间,以及Metabase为应对此事所采取的措施。根据Metabase官网上一则博客文章,有人利用一个“未知(零日)漏洞”访问了数据,Metabase现已识别并修补了该漏洞。该提供商的调查结果和安全建议目前仍属“初步”阶段。“我们正在与一家第三方取证调查公司合作,以了解该事件的完整性质和范围,”Metabase在发给框架公司的邮件中表示。

框架公司方面表示,在收到泄露通知后已轮换其凭据,并“确认管理权限没有发生变更,Metabase以外的系统也没有被访问”。该公司还表示,正在“审查并改进其在外部数据库供应商处存储数据的方法”。

对于框架公司来说,这次数据泄露来得实在不是时候。尽管今年早些时候公布了令人兴奋的新产品阵容,但该公司在持续的存储芯片短缺中比大多数同行更为挣扎。框架公司首先于1月宣布涨价,随后又在3月再次提价。在新款框架笔记本Pro开启预售不久后,该公司还被迫在部分预订单中搭载比宣传更少的RAM以应对不断上涨的组件成本,并向不愿接受的客户提供全额退款。

英文来源:

Framework customer information was accessed as part of a data breach
The company says payment details weren't exposed.
Framework, maker of deliberately repairable and upgradeable computers, has notified all of its customers that their data was exposed in a breach. According to an email the company sent late Thursday, August 6, customer names, login IPs, addresses, phone numbers and emails were accessed during a hack of the company's business database provider Metabase. Payment information was not included in the breach.
The company included Metabase's explanation in its own email, which details when the provider identified the attack on August 3 and the actions Metabase took to address it. According to a blog on Metabase's own website, someone used an "unknown (0-day) vulnerability" to access data, which Metabase has now identified and patched. The provider's findings and security recommendations are "preliminary" as of now. "We are working with a third-party forensic investigation firm to understand the full nature and scope of the event," Metabase shared in an email to Framework.
Framework, for its part, says it rotated its credentials after it was notified of the breach and "confirmed that there were no changes in admin access or access to systems outside of Metabase." The company says it's also "reviewing and improving [its] methodology for data storage in external database vendors."
A data breach couldn't have come at a worse time for Framework. Despite announcing an exciting lineup of new products earlier this year, the company has struggled with the ongoing memory shortage more than most. Framework first announced it was raising prices in January, and then raised them again in March. Not long after collecting preorders for the new Framework Laptop Pro, the company was also forced to include less RAM than advertised in some preorders to account for the growing cost of components and extend a full refund to customers who weren't willing to pay.

Engadget

文章目录


    扫描二维码,在手机上阅读