Framework, all customers notified of data breach via Metabase zero-day

Original: Computer maker Framework notifies ‘all customers’ of a data breach

Why This Matters

The breach highlights supply-chain risk when SaaS providers are targeted via zero-day exploits, exposing entire customer bases.

Modular PC maker Framework confirmed a data breach affecting all of its customers after business intelligence provider Metabase was hacked via a zero-day vulnerability. Stolen data includes names, email addresses, phone numbers, and physical addresses. Payment information was not compromised.

Framework, the company known for modular and repairable computers, has notified its entire customer base of a data breach stemming from a cyberattack on Metabase, a third-party business intelligence provider. The breach was disclosed after multiple Framework customers reported receiving notification emails on August 7, 2026.

Framework spokesperson Eric Schumacher confirmed to TechCrunch that the breach affected "all customers," but declined to provide a specific number. Framework is considered a niche brand, though industry estimates suggest the company has sold hundreds of thousands of devices.

According to the breach notification reviewed by TechCrunch, Metabase was compromised via a previously unknown security vulnerability — a zero-day exploit — that granted hackers access to customer databases hosted on Metabase's cloud servers. Metabase disclosed the incident on its official website, stating an attacker used the zero-day to access customer cloud instances.

Framework's notification also included a copy of the email Metabase sent to the company, confirming that Framework's cloud instance was accessed. The investigation found that customer personal data — names, email addresses, phone numbers, and physical addresses — was stolen. No payment information was affected. Metabase did not respond to TechCrunch's request for comment.

Source

techcrunch.com — Read original →