Framework built its reputation on trust — the promise that you can take your own laptop apart and fix it yourself. But this time, the breach happened somewhere entirely outside its control. On the evening of August 6, the company known for its repairable, upgradeable laptops emailed all customers to inform them that personal data had been accessed in a breach — not because of an issue with Framework's own systems, but through Metabase, the third-party service provider it uses to manage business data.
According to Metabase's explanation cited in Framework's email, the company discovered on August 3 that someone had exploited an "unknown (0-day) vulnerability" to access data. The vulnerability has since been identified and patched. Metabase said it is working with a third-party forensic investigation firm to determine the full scope and scale of the incident, and that its current findings and security recommendations remain "preliminary."
The exposed data includes customers' names, login IPs, addresses, phone numbers, and email addresses. Payment information was not included — a point Framework specifically emphasized. After being notified, the company reset the relevant credentials and confirmed that "no administrative privileges were changed, and there is no evidence that any systems beyond Metabase were accessed." Framework also said it would review and improve how it hands data over to external database vendors.







