READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Framework Tells All Customers Their Data Was Stolen in Metabase Breach

Framework Tells All Customers Their Data Was Stolen in Metabase Breach
Framework, the repairable-laptop company, notified every customer that hackers stole names, emails, phone numbers and addresses through a zero-day attack on its analytics vendor Metabase. Payment data wasn't touched, but the breach lands right as Framework is already dealing with price hikes and RAM shortages.

Framework, the company known for building laptops you can actually repair yourself, told its entire customer base this week that their personal data got stolen. Not some customers. All of them.

The breach didn't happen at Framework directly. It happened at Metabase, a business intelligence provider Framework uses to store and analyze customer data in the cloud. According to TechCrunch, Framework spokesperson Eric Schumacher confirmed the breach hit "all customers" but wouldn't give a specific number. Framework doesn't sell at Apple or Dell scale, but estimates put its device sales in the hundreds of thousands, according to TechCrunch.

Names, email addresses, phone numbers, physical addresses, and login IPs were taken. Engadget reported the same data set based on the email Framework sent customers late Thursday, August 6. Both outlets confirm one important detail: payment information was NOT part of the breach.

Metabase says the attacker used what's called a zero-day, an unknown security flaw nobody had patched yet because nobody knew it existed. Metabase disclosed the breach on its own website, saying the hacker exploited the bug to reach into customer databases hosted on Metabase's cloud servers. The company identified the attack on August 3 and says it has since found and patched the vulnerability, according to Engadget.

Metabase called its own findings "preliminary" and said it's working with a third-party forensic investigation firm to nail down the full scope. That's a normal step after a breach like this, but it also means the company doesn't yet have a complete picture of what happened or how far it spread.

Framework's response, based on the email it sent customers, was to rotate its credentials once notified and check whether the attacker got into anything beyond the Metabase system. The company says it "confirmed that there were no changes in admin access or access to systems outside of Metabase." Framework also says it's reviewing how it stores data with outside vendors going forward.

Neither Metabase nor Framework has said how many total records were exposed, or which countries' customers were affected. Metabase did not respond to TechCrunch's request for comment. If a zero-day let someone into Metabase's cloud infrastructure, there's a legitimate question about whether other companies using Metabase got hit too, and neither Framework nor Metabase has addressed that publicly.

This breach lands at a rough moment for Framework. Engadget noted the company has spent 2026 raising prices twice, once in January and again in March, blaming a memory shortage that's squeezed the whole PC industry. Framework also had to ship its new Laptop Pro with less RAM than customers ordered because component costs spiked, and it offered full refunds to buyers who didn't want to accept the downgrade.

None of that is related to the breach. But it means a company already taking heat over pricing and supply problems now has to explain to every single customer why their address and phone number ended up in a hacker's hands.

The growing practice of companies handing customer data to third-party analytics vendors for business intelligence purposes often leaves them with limited visibility or control when that vendor gets breached. Framework didn't get hacked. Its vendor did. But Framework's customers are the ones dealing with the fallout.

There's no indication yet that financial fraud has resulted from this breach, since payment data wasn't part of what was stolen. But names, addresses, phone numbers and emails are exactly the ingredients scammers use for phishing attempts and social engineering. Framework customers should expect a wave of suspicious emails and texts pretending to be from the company in the weeks ahead.

Still unresolved: how many total customers were affected, whether other Metabase clients got breached through the same zero-day, and what Metabase's third-party forensic investigation eventually turns up. Framework says it's improving its vendor data practices, but hasn't detailed what that actually means or when those changes take effect.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
TechCrunchComputer maker Framework notifies ‘all customers’ of a data breach
center-left
EngadgetFramework customer information was accessed as part of a data breach