Framework suffers data breach affecting all its customers
A zero-day exploit in Metabase exposes names, emails, phones, and addresses of all Framework customers
August 8, 2026 · 4 min read
TL;DR: Framework has notified all its customers of a data breach exposing names, emails, phones, and addresses. The attack occurred through a zero-day exploit in the Metabase BI service. No payment data was compromised.
What happened
Framework, the American company famous for its modular and sustainable laptops, has confirmed a data breach affecting all its customers. As reported by TechCrunch on August 7, 2026, the company sent email notifications to all its customers stating that an attacker accessed their names, email addresses, phone numbers, and physical addresses.
The origin of the incident traces back to a zero-day exploit in Metabase, a business intelligence (BI) service that Framework used for data analysis. Metabase revealed on its own blog that it was hacked through an unknown vulnerability that allowed attackers to access its customers' databases hosted on its cloud servers.
In the email sent to customers, Framework included the communication that Metabase sent them, explaining that hackers had accessed their cloud instance. The company investigated the incident and determined that attackers stole customers' personal data, but did not include payment information.
Why it matters
This incident is significant for several reasons. First, it affects all Framework customers, a company that, although niche, has sold hundreds of thousands of devices according to some estimates. This means a large number of people are potentially exposed to risks such as phishing, identity fraud, or account theft.
Second, the breach occurred through a third-party provider (Metabase), highlighting the inherent risks in the software supply chain. Even companies with strong security measures can be compromised by vulnerabilities in third-party services. This is a reminder that security is only as strong as the weakest link in the chain.
Additionally, the attack used a zero-day exploit, meaning a vulnerability unknown to the provider and without a patch available at the time of the attack. This underscores the difficulty of protecting against unknown threats and the importance of having incident response plans and continuous monitoring.
Consequences for customers and the company
For Framework customers, the immediate consequences include an increased risk of phishing and identity theft, as attackers possess personal data that can be used to make fraudulent emails appear legitimate. They may also face phone or postal fraud attempts, given that phone numbers and physical addresses were exposed.
For Framework, the incident is a hard blow to its reputation as a company focused on privacy and sustainability. The company will need to invest in additional security measures, offer credit monitoring services to those affected, and possibly face lawsuits or regulatory fines, depending on applicable data protection laws (such as GDPR in Europe or CCPA in California).
Furthermore, this incident could affect consumer trust in the brand, especially among its most enthusiastic and technical user base, who value transparency and control over their data.
What readers should know
If you are a Framework customer, you have likely received a notification email. You should:
- Change your passwords for your Framework account and any other service where you used the same password.
- Be alert to suspicious emails or calls requesting additional information or attempting to impersonate Framework or Metabase.
- Consider freezing your credit or activating fraud alerts with credit bureaus.
- Monitor your bank and credit card accounts for unusual activity.
Framework has stated that it is investigating whether the breach also affected customers of Framework for Business, its enterprise program. So far, no further details have been revealed about the exact number of affected individuals or the full scope of the attack.
Metabase, for its part, has published a statement on its official blog acknowledging the attack and stating that it is working to fix the vulnerability and notify all affected customers. However, security experts recommend that companies using Metabase review their access logs and consider rotating credentials.
Context and comparisons
This incident adds to a series of data breaches in 2026, such as the one suffered by AT&T earlier this year, which exposed call and message data of millions of customers. It also recalls the LastPass breach in 2022, where attackers accessed customer data through a compromise of an employee and a vulnerability in a third-party service.
The peculiarity here is that the attack occurred through a BI service, a component that many companies consider low-risk in terms of personal data, but which can contain sensitive information if used to analyze customer data. This underscores the need to assess risks across the entire software supply chain, including internal and analytics tools.
Recommendations for businesses
For companies using third-party services, this incident offers several lessons:
- Conduct a thorough risk assessment of all vendors, including software-as-a-service (SaaS) providers.
- Implement additional security measures, such as multi-factor authentication and encryption of data at rest and in transit.
- Establish incident response plans that include communication with customers and regulatory authorities.
- Continuously monitor security advisories from vendors and apply patches promptly.
In summary, the data breach at Framework is a reminder that data security is a shared responsibility between the company and its vendors. Customers should take proactive steps to protect themselves, and businesses should review their own third-party dependencies.