Description

California-based laptop manufacturer Framework Computer has revealed a data breach that exposed the personal information of an undisclosed number of customers. The breach occurred after Keating Consulting Group, the company's accounting service provider, fell victim to a phishing attack. On January 11, an attacker impersonating Framework's CEO tricked a Keating Consulting accountant into sharing a spreadsheet containing customers' personally identifiable information (PII), including full names, email addresses, and outstanding balances associated with Framework purchases. The breach was discovered when Framework's Head of Finance was alerted 29 minutes after the accountant responded to the phishing email. In response, Framework conducted an investigation to identify affected customers and promptly notified them via email. The exposed data could potentially be used in phishing attacks targeting customers for payment information or leading them to malicious websites. Framework emphasized that it only sends emails from 'support@frame.work' regarding failed payments and never requests payment information via email. Customers were urged to contact the support team if they receive suspicious emails. Going forward, all Keating Consulting employees with access to Framework customer information will undergo mandatory phishing and social engineering attack training. Framework will also audit their standard operating procedures for information requests. Additionally, the company will conduct audits on the training and procedures of all other accounting and finance consultants with access to customer information. The number of affected customers has not been disclosed at this time.