Computer maker Framework notifies 'all customers' of a data breach
TechCrunch
β’Fri, 07 Aug 2026 16:09:04 +0000
π° What Happened
Framework, which makes modular repairable computers, notified all of its customers that hackers stole their names, email addresses, phone numbers and physical addresses. The company attributed the breach to an upstream cyberattack at Metabase, a business-intelligence firm hacked via an unknown zero-day flaw that allowed access to customers' databases on its cloud servers. Framework said payment information was not stolen, and Metabase did not respond to a request for comment.
π The Backstory
Framework laptop makers are a relatively niche but high-profile modular laptop brand, with estimates suggesting it has sold hundreds of thousands of devices. The breach originated with a third-party supplier, highlighting the supply-chain risks that affect even security-conscious companies. The incident underscores how a compromise at a single business-intelligence provider can cascade to downstream customer data across many organisations.
π― Why It Matters
The breach demonstrates the growing threat of supply-chain attacks, where a vulnerability in a third-party provider exposes data held across many companies. For consumers, it highlights how personal information can leak even from firms with strong privacy reputations. The incident adds to ongoing concern about the security of software and data-processing layers that sit beneath consumer-facing products.
Framework, which makes modular repairable computers, notified all of its customers that hackers stole their names, email addresses, phone numbers and physical addresses. The company attributed the breach to an upstream cyberattack at Metabase, a business-intelligence firm hacked via an unknown zero-day flaw that allowed access to customers' databases on its cloud servers. Framework said payment information was not stolen, and Metabase did not respond to a request for comment.
Framework laptop makers are a relatively niche but high-profile modular laptop brand, with estimates suggesting it has sold hundreds of thousands of devices. The breach originated with a third-party supplier, highlighting the supply-chain risks that affect even security-conscious companies. The incident underscores how a compromise at a single business-intelligence provider can cascade to downstream customer data across many organisations.
The breach demonstrates the growing threat of supply-chain attacks, where a vulnerability in a third-party provider exposes data held across many companies. For consumers, it highlights how personal information can leak even from firms with strong privacy reputations. The incident adds to ongoing concern about the security of software and data-processing layers that sit beneath consumer-facing products.