Supply chain β›“ Supply Chain

Framework Computer Third-Party Breach (January 2024)

πŸ“… 2024-01-01 🏒 Keating Consulting Group
Primary Source β†—

Incident Details

Framework discloses data breach after accountant gets phished. Framework Computer disclosed a data breach exposing the personal information of an undisclosed number of customers after Keating Consulting Group, its accounting service provider, fell victim to a phishing attack. The California-based manufacturer of upgradeable and modular laptops says a Keating Consulting accountant was tricked on January 11 by a threat actor impersonating Framework’s CEO into sharing a spreadsheet containing customers’ personally identifiable information (PII) “associated with outstanding balances for Framework purchases.”. “On January 9th, at 4:27am PST, the attacker sent an email to the accountant impersonating our CEO asking for Accounts Receivable information pertaining to outstanding balances for Framework purchases,” the company says in data breach notification letters sent to affected individuals. Third-party company: Keating Consulting Group.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Keating Consulting Group
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2024-01-01 Breach occurred
  2. 2024-01-11 Publicly disclosed