Framework, a company that makes modular repairable computers, said it has notified all of its customers that hackers stole their names, email addresses, phone numbers, and physical addresses, due to an incident at a company that provides business intelligence.
On Thursday, several Framework customers said on social media that they had received an email from the company notifying them of the data breach.
Framework’s spokesperson Eric Schumacher told TechCrunch that the breach affected “all customers,” but declined to specify a specific number. Framework computers are relatively niche products, but some estimates say the company sold hundreds of thousands of devices.
According to the notification seen by TechCrunch, the company blamed the data breach on an upstream cyberattack at Metabase.
Metabase disclosed its own breach in a blog post on its official website, where it said that it was hacked by someone using an unknown security flaw, a so-called zero-day. The company said the hackers exploited the bug to give them the ability to access customers’ databases stored on Metabase’s cloud servers.
In its email to customers, Framework also included the email Metabase sent to the company, which says hackers accessed Framework’s cloud instance. The computer maker said it investigated the incident and found that hackers had stolen its customers’ personal data, but did not include their payment information.
Metabase did not respond to a request for comment.
{content}
Source:{feed_title}
—
Framework Confirms Massive Customer Data Breach Stemming from Metabase Zero-Day Exploit
Modular PC maker’s entire customer base impacted by upstream supply chain attack.
Key Takeaways
- Universal Impact:Framework has confirmed that a data breach has affected *all* of its customers, though a precise number remains undisclosed, potentially impacting hundreds of thousands.
- Upstream Vulnerability:The breach originated from a sophisticated “zero-day” exploit targeting Metabase, a third-party business intelligence provider used by Framework, leading to unauthorized access to Framework’s cloud instance.
- Personal Data Compromised:Stolen data includes customer names, email addresses, phone numbers, and physical addresses. Crucially, payment information was *not* accessed in the incident.
Framework, the innovative company celebrated for its modular, repairable laptops, has sent shockwaves through its customer base by disclosing a significant data breach. The incident, which Framework attributes to an “upstream cyberattack” on its business intelligence provider, Metabase, has resulted in the theft of personal information for every single Framework customer. This incident underscores the pervasive and often invisible risks posed by third-party vendor relationships in today’s interconnected digital landscape.
The Breach Unfolds: Framework’s Disclosure
On Thursday, Framework customers began reporting on social media that they had received an email from the company notifying them of the breach. The notification, later seen by TechCrunch, detailed the scope of the compromise. According to Framework, the stolen data includes customers’ names, email addresses, phone numbers, and physical addresses. A critical piece of information that was *not* compromised, Framework assured, was payment information, offering a degree of relief amidst the concern.
While Framework spokesperson Eric Schumacher confirmed that “all customers” were affected, the company has refrained from providing a specific count of individuals impacted. Given that Framework, despite its niche appeal, has reportedly sold hundreds of thousands of devices, this implies a substantial number of individuals have had their personal data exposed. The company’s ethos, often appealing to privacy-conscious and tech-savvy users, makes this breach particularly ironic and potentially more sensitive for its community.
Upstream Attack: The Metabase Connection
The root cause of Framework’s data exposure lies not within its own systems directly, but with Metabase, a third-party vendor providing business intelligence services. Metabase had previously disclosed its own breach in a blog post, revealing that it had fallen victim to a sophisticated attack leveraging a “zero-day” vulnerability. A zero-day exploit refers to a software flaw that is unknown to the vendor and thus has no patch available, making it incredibly difficult to defend against.
Hackers exploited this unknown flaw to gain access to customer databases stored on Metabase’s cloud servers. In its communication to customers, Framework included the email it received from Metabase, confirming that Framework’s specific cloud instance was among those accessed by the attackers. While Framework conducted its own investigation to confirm the extent of its customer data compromise, Metabase has not yet responded to requests for comment regarding the specifics of the zero-day or its wider impact.
Understanding the Impact: What the Compromised Data Means
The theft of Personally Identifiable Information (PII) like names, email addresses, phone numbers, and physical addresses carries significant risks for affected individuals. While payment information was not stolen, this combination of data is a goldmine for malicious actors looking to launch targeted phishing campaigns, social engineering attacks, or even more serious identity theft attempts.
Customers should be acutely aware of an increased likelihood of receiving fraudulent emails, text messages, or phone calls impersonating Framework or other trusted entities. These scams could attempt to trick users into divulging more sensitive information, clicking on malicious links, or installing malware. The detailed nature of the stolen data—including physical addresses—could also potentially be used in more sophisticated scams or even physical targeting, though such instances are rarer.
The Supply Chain Security Challenge
This incident serves as a stark reminder of the escalating challenge of supply chain security. In an era where companies rely on a vast ecosystem of third-party vendors for everything from cloud hosting to analytics, the security posture of even the most diligent organization is only as strong as its weakest link. A breach at one vendor, like Metabase in this case, can ripple outwards, compromising the data of multiple downstream clients, regardless of their internal security measures.
For businesses, this highlights the critical need for rigorous due diligence when selecting and monitoring third-party providers, demanding robust security protocols, and understanding the potential risks associated with data sharing. For consumers, it underscores the reality that even when choosing companies with strong privacy commitments, data can still be exposed through vulnerabilities in their vendor network.
What Should Framework Customers Do?
Affected Framework customers are advised to take several immediate steps to protect themselves:
- Be Vigilant:Exercise extreme caution with any unsolicited communications (emails, texts, calls) that claim to be from Framework, other companies, or financial institutions. Verify the sender’s legitimacy independently before clicking links or providing information.
- Strengthen Passwords:If you’ve used the same email address for your Framework account as for other services, consider updating your passwords for those other services, especially if you tend to reuse passwords.
- Enable Multi-Factor Authentication (MFA):Activate MFA on all your online accounts, particularly email, banking, and social media. This adds an extra layer of security beyond just a password.
- Monitor Accounts:Keep a close eye on your financial statements and credit reports for any suspicious activity, even though payment data wasn’t directly stolen.
- Consider Email Aliases:If you use email aliases, be aware that the compromised email address might now be targeted.
Bottom Line
The data breach at Framework, originating from a sophisticated zero-day attack on its third-party vendor Metabase, is a sobering reminder of the interconnected vulnerabilities in our digital ecosystem. Even companies like Framework, which champion transparency and user control, are not immune to the cascading effects of supply chain compromises. This incident reinforces that proactive security measures, stringent vendor management, and constant user vigilance are no longer optional but essential safeguards against an ever-evolving threat landscape. As the digital world becomes more intertwined, shared responsibility for cybersecurity becomes paramount for both corporations and consumers alike.

