Framework, the maker of modular, repairable computers, has notified all of its customers that hackers stole their personal data — including names, email addresses, phone numbers, and physical addresses — in a breach disclosed in August 2026.
The breach originated at Metabase, a business intelligence provider used by Framework. Metabase disclosed in a blog post that an attacker exploited a previously unknown security flaw — a zero-day vulnerability — to gain access to customer databases stored on Metabase’s cloud servers. Hackers were able to access Framework’s cloud instance through that same exploit.
Framework spokesperson Eric Schumacher confirmed to TechCrunch that the breach affected “all customers,” though he declined to provide a specific number. Framework computers are described as relatively niche products, though some estimates suggest the company has sold hundreds of thousands of devices.
Framework’s notification email to customers also included a copy of the message Metabase sent to Framework about the incident. The company said its own investigation confirmed that customer personal data was stolen, but that payment information was not compromised.
Several Framework customers reported receiving the breach notification email on Thursday, sharing news of it on social media. Metabase did not respond to a request for comment from TechCrunch.
Because the breach stems from an attack on a third-party vendor rather than Framework’s own systems directly, the incident highlights how a cyberattack on a single upstream provider can expose the data of an entire customer base. Affected Framework customers may want to be alert to phishing attempts or other communications that use their compromised personal details.
Source: TechCrunch