I got the breach notification today. Earlier this week I got an “Action Required” email asking me to update my payment method before my laptop would ship.
I always handle emails like these by ignoring the button and logging in directly at the relevant website (this time Framework). It worked out well, and the email was clearly legitimate.
But I’d like to flag the pattern. A phishing email built off the breached data would look almost exactly like the one I received: same sender name, same layout, same urgency, same big button to update payment information.
I understand that Framework likely will not strip the link entirely, as it will make the friction of updating payment info too much for some users. But I would suggest that the email primarily asks the customer to log in through the web site and not through a link.
Most Nordic banks dropped payment links from customer emails years ago for this reason. As far as I know this has not been a problem. Given that Framework customers are now a known list of names and addresses, it seems worth revisiting.
Thanks for disclosing the breach quickly. That was handled very well. As I am now awaiting the delivery of my laptop, I will be even more vigilant than normal if I receive an email on import fees etc. that could be a targeted phishing attempt.