Framework notifies all customers of data breach following Metabase cyberattack
Hackers exploited a zero-day vulnerability to access business intelligence provider Metabase, which hosts Framework’s cloud instance, prompting widespread customer notifications.

Modular computer manufacturer Framework has confirmed a data breach affecting its entire customer base, following a cyberattack on Metabase, a business intelligence provider. The incident resulted in the theft of personal information, including names, email addresses, phone numbers, and physical addresses. Framework spokesperson Eric Schumacher confirmed to TechCrunch that the breach impacted “all customers,” though the company declined to provide specific figures regarding the total number of affected individuals.
The breach was triggered by an upstream attack on Metabase, which hosts customer databases on its cloud servers. In a blog post disclosing the incident, Metabase stated that hackers exploited an unknown security flaw, commonly referred to as a zero-day vulnerability, to access its systems. The company confirmed that this exploit allowed attackers to gain entry to customer databases, including Framework’s cloud instance.
Framework notified its user base via email, with several customers reporting receipt of the alert on Thursday. The notification included an internal email from Metabase to Framework, confirming that the attackers had accessed the computer maker’s cloud instance. The company conducted an investigation into the incident and determined that while personal data was compromised, payment information was not affected.
Framework, known for its niche line of modular and repairable computers, has sold an estimated hundreds of thousands of devices globally. The scope of the breach means that every customer with an account on the platform has been impacted, although the precise volume of affected users remains undisclosed. The company has not yet released further details on the specific nature of the zero-day vulnerability or the extent of the data exfiltration.
Metabase has not responded to requests for comment regarding the incident or its liability for the security failure. The breach highlights the risks associated with third-party service providers in the technology supply chain, as upstream vulnerabilities can cascade to downstream clients. Framework has advised customers to remain vigilant, though no specific remediation steps were detailed in the initial notification.
