Framework, the startup known for building modular, repairable laptops, has told customers that hackers stole personal information belonging to its entire user base. The Framework data breach did not start inside the company’s own systems, though. It traces back to Metabase, a business intelligence provider that Framework relies on, which was hit by attackers exploiting a previously unknown security flaw.
Summary
Key takeaways
- Framework notified all customers that hackers accessed their names, email addresses, phone numbers, and physical addresses.
- The breach originated upstream at Metabase, a business intelligence provider used by Framework.
- Metabase says it was hacked through an unknown zero-day vulnerability that let attackers reach customer databases stored on its cloud servers.
- Framework says payment information was not compromised, though it declined to say how many customers were affected.
- Metabase did not respond to requests for comment from TechCrunch.
Framework Notifies All Customers of Data Breach
Framework confirmed that every customer in its database was touched by the incident, though the company has not put a number on how many people that actually represents. Eric Schumacher, a spokesperson for Framework, according to statements made to TechCrunch, the security incident impacted the entirety of the customer base, though a precise figure was not disclosed when pressed.
That vagueness matters. Framework makes relatively niche computers, but some estimates cited by TechCrunch suggest the company has sold hundreds of thousands of devices since launching. If even a fraction of that customer base had accounts tied to the compromised systems, the exposure could stretch well beyond a small circle of buyers.
Scope of the Breach
News of the incident first surfaced not through an official press release but through customers themselves. On Thursday, several Framework buyers posted on social media that they had received an email notifying them their data had been exposed. Framework later confirmed the notification was genuine and tied it directly to the Metabase cyberattack.
Customer Notification
In its message to affected users, Framework included a copy of the notification email that Metabase had sent the company, which stated that hackers had accessed Framework’s cloud instance. Framework said it investigated the incident internally and confirmed that stolen data did not include payment information, offering at least some reassurance to customers worried about financial exposure.
Origin of the Breach: Metabase Cyberattack
The root cause of the Framework data breach sits with a third-party vendor, not with Framework’s own infrastructure. Metabase, the business intelligence company Framework used, publicly disclosed on its own website that it had been breached by an attacker exploiting a security flaw nobody had previously identified.
Use of an Unknown Zero-Day Vulnerability
Metabase described the intrusion as the work of someone using an unknown zero-day, a type of vulnerability that has no existing patch because the vendor itself wasn’t aware it existed. Zero-days are especially dangerous precisely because there’s no defense ready when they’re first exploited, giving attackers a window to move before anyone can respond.
Cloud Server Access
According to Metabase’s own account, the hackers used that flaw to gain access to customer databases hosted on its cloud servers. That access reportedly extended to Framework’s cloud instance specifically, which is how attackers ended up pulling personal records tied to Framework’s user base rather than Metabase’s own accounts.
Types of Customer Data Compromised
The categories of stolen information are consistent with what’s typically valuable for phishing and identity-related fraud rather than direct financial theft. Hackers made off with customers’ names, email addresses, phone numbers, and physical addresses, according to Framework’s notification.
Framework has stressed that payment details were not part of what was taken, based on its internal investigation. Still, names paired with contact details and home addresses are often enough to fuel targeted phishing attempts, so affected customers may want to stay alert to unexpected emails or calls referencing their Framework purchase.
Why This Incident Matters Beyond Framework
This case is a reminder that a company’s security posture is only as strong as the vendors it depends on. Framework didn’t lose control of its own servers — it lost control of customer data because a partner it trusted with business intelligence services got hacked first. That’s an increasingly common pattern as companies outsource analytics, cloud storage, and other backend functions to third-party platforms.
For customers, the practical takeaway is that a breach doesn’t have to happen at the company they bought a product from to still put their personal information at risk. For businesses evaluating vendors, the Metabase cyberattack underscores how upstream software dependencies can quietly become the weakest link in an otherwise well-defended system.
Metabase did not respond to TechCrunch’s request for comment, leaving unanswered questions about how the zero-day was ultimately identified, how many other customers beyond Framework may have been affected, and what steps the company has taken since to prevent a repeat incident.
FAQ
What data was stolen in the Framework data breach?
Names, email addresses, phone numbers, and physical addresses were stolen in the breach.
How did the data breach at Framework occur?
The breach occurred due to an upstream cyberattack on Metabase, which exploited an unknown zero-day vulnerability to access cloud databases.
Was payment information compromised in the Framework breach?
Framework states that payment information was not compromised in the breach.
Has Framework disclosed how many customers were affected?
Framework declined to specify the exact number of affected customers but said all customers were impacted.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

