🔐
Security 📅 2026-08-08 · 04:19 AM IST ⏱ 3 min read

Major Data Breach Affects Millions After Software Flaw Exploited

Hackers exploited a security hole in popular business software to steal data from 3.8 million people across multiple companies.

A Major Security Incident Unfolds

A significant data breach has compromised the personal information of approximately 3.8 million individuals after criminals discovered and weaponized a serious vulnerability in widely-used business software. The attacks targeted Unlimited Technology Systems, exploiting a flaw in Metabase—a tool many companies use to organize and analyze their data. Cybercriminals discovered this weakness before the software makers could fix it, giving them a window of opportunity to break into customer systems undetected.

The breach affected at least two major companies, Framework and Tally, which relied on this software to manage sensitive customer records. Rather than simply accessing data, the attackers actively stole information, suggesting this was a carefully planned operation targeting valuable customer databases.

What This Means

Think of this vulnerability like a locked door with a hidden master key that thieves found before the locksmith knew it existed. The specific flaw—called a SQL injection vulnerability—allows attackers to trick the software into revealing information it normally keeps hidden. By inserting special commands into search fields or data entry boxes, hackers can bypass security measures and access everything stored in the system.

What makes this particularly serious is that the weakness was unknown to the software developers themselves. This "zero-day" vulnerability gave criminals free rein to attack systems for an extended period before anyone realized the danger. The hackers specifically targeted instances where companies were running this software, meaning they likely conducted reconnaissance to identify which organizations would yield the most valuable information.

Why You Should Care

If you've interacted with Framework, Tally, or other services using this Metabase software, your personal data may have been compromised. This could include:

This matters because stolen data creates multiple dangers. Criminals can use personal information to commit identity theft, access your financial accounts, or sell your data to other bad actors. You might face unauthorized charges, receive fraudulent communications, or discover someone has opened accounts in your name.

For businesses, this incident serves as a stark reminder that even trusted software tools can become entry points for attackers. Companies may face legal consequences, lose customer trust, and spend millions addressing the fallout.

What You Can Do

If you believe you may be affected, take these protective steps immediately:

Companies using similar software should urgently apply security patches and audit their systems for unauthorized access, while individuals should remain vigilant about protecting the sensitive information that remains in their hands.

📎 This is original ITVedas reporting. This story was inspired by coverage from bleepingcomputer.com. Visit the source for their original reporting.

Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.

Explore IT Chapters →