Framework notifies customers of data breach following Metabase cyberattack
The breach, identified on 3 August 2026, exploited an unknown vulnerability in the database provider’s systems. Framework has rotated credentials and is reviewing its data storage practices.

Framework, a computer manufacturer known for its repairable devices, has notified customers that their personal data was accessed during a cyberattack on its business database provider, Metabase. The breach was identified by Metabase on 3 August 2026 and exploited an unknown vulnerability. The incident exposed customer names, login IPs, addresses, phone numbers, and email addresses.
Framework confirmed that payment information was not compromised in the incident. The company sent notification emails to customers late on Thursday, 6 August, including Metabase’s explanation of the event. Metabase has identified and patched the vulnerability used in the attack, describing its initial findings as preliminary.
In response to the breach, Framework rotated its credentials and confirmed there were no changes in admin access or access to systems outside of Metabase. The company stated it is reviewing and improving its methodology for data storage with external database vendors.
Metabase is working with a third-party forensic investigation firm to determine the full nature and scope of the event. The provider’s security recommendations are currently under review as the investigation continues.
The data breach occurs against a backdrop of recent operational challenges for Framework. The company has faced ongoing difficulties with memory shortages and raised prices in January and again in March. Preorders for the new Framework Laptop Pro were also affected by component cost increases, leading to some orders being fulfilled with less RAM than advertised.
