Supply chain
β Supply Chain
Framework Computer Third-Party Breach (January 2024)
Primary Source βIncident Details
Framework discloses data breach after accountant gets phished. Framework Computer disclosed a data breach exposing the personal information of an undisclosed number of customers after Keating Consulting Group, its accounting service provider, fell victim to a phishing attack. The California-based manufacturer of upgradeable and modular laptops says a Keating Consulting accountant was tricked on January 11 by a threat actor impersonating Framework’s CEO into sharing a spreadsheet containing customers’ personally identifiable information (PII) “associated with outstanding balances for Framework purchases.”. “On January 9th, at 4:27am PST, the attacker sent an email to the accountant impersonating our CEO asking for Accounts Receivable information pertaining to outstanding balances for Framework purchases,” the company says in data breach notification letters sent to affected individuals. Third-party company: Keating Consulting Group.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Keating Consulting Group
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2024-01-01 Breach occurred
- 2024-01-11 Publicly disclosed