Framework, the company known for making modular, repairable laptops, notified its entire customer base of a data breach in early August 2026. Unlike many breaches, the attack didn’t originate inside Framework’s own systems — it started at Metabase, a business intelligence platform Framework uses to analyze its own data.

According to the timeline Framework shared with customers, Metabase discovered on August 3, 2026, that an attacker had exploited a previously unknown vulnerability — a zero-day, meaning a flaw attackers found and used before the software’s developers even knew it existed — in its cloud service. Metabase notified Framework of the breach on August 6 at 9 a.m. Pacific time, confirming that Framework’s own instance had been accessed. Framework says it reviewed the logs Metabase provided and confirmed that customer information had indeed been reached.

What Information Was Exposed

Framework has confirmed that attackers accessed customer names, email addresses, phone numbers, physical addresses, and login IP addresses. For Framework for Business customers, the company said it’s still investigating whether additional information — including company names, VAT or Employer Identification Numbers, and billing email addresses — may also have been accessed.

Importantly, Framework says payment information and order records were not part of the breach. A company spokesperson told TechCrunch that the incident affected “all customers,” though the company has not disclosed a specific number of people impacted.

How the Attack Worked

According to Metabase’s own disclosure, the attacker exploited a critical zero-day SQL injection vulnerability affecting Metabase Cloud versions 1.58 and above. Security researchers describe the flaw as serious specifically because it allowed an unauthenticated attacker to inject arbitrary commands into the underlying application database — potentially granting administrator-level access to whichever company’s instance was targeted. Metabase has said the vulnerability did not yet have a formal CVE tracking number at the time of disclosure. The company blocked the endpoints used in the attack, patched the flaw, and says it has already upgraded its cloud customers to the fixed version.

Framework, for its part, said it rotated credentials for every database connected to its Metabase instance immediately after being notified, and reported finding no evidence of unauthorized administrator-access changes or that the intrusion spread beyond the Metabase connection itself.

A Breach That Starts With a Vendor, Not the Company

This kind of incident — sometimes called a supply-chain or third-party breach — has become increasingly common as companies rely on outside vendors to handle everything from customer support to internal analytics. Framework didn’t get hacked directly; a tool it trusted with its data did. In its notice to customers, Framework acknowledged this directly, saying it is “reviewing and improving our methodology for data storage in external database vendors” going forward, and that it’s in the process of notifying relevant regulators in regions where breach-notification rules apply.

What Framework Customers Should Do

The information exposed in this breach — names, emails, phone numbers, and physical addresses — doesn’t include passwords or payment details, so there’s no indication that accounts or financial information were directly compromised. That said, this combination of contact details is exactly what scammers use to craft convincing phishing messages, since a message referencing your real name, address, or a recent Framework purchase can feel far more legitimate than a generic scam attempt. Framework customers should be especially cautious of unexpected emails or texts claiming to be from Framework in the coming weeks, avoid clicking links in unsolicited messages, and verify any communication directly through Framework’s official website rather than replying to or clicking through an email.