Framework Notifies All Customers of Data Breach via Metabase Zero-Day
Modular laptop maker Framework suffered a total customer data leak after attackers exploited a vulnerability in a third-party business intelligence provider.
Modular laptop manufacturer Framework has notified its entire customer base of a significant data breach resulting from an upstream cyberattack. The incident exposed the personal contact information of every individual in the company's database, though the firm confirmed that payment data remained secure.
The breach occurred when attackers exploited a zero-day vulnerability within the cloud servers of Metabase, a business intelligence (BI) provider used by Framework to manage its data. According to Eric Schumacher, a spokesperson for Framework, the security incident "impacted the entirety of the customer base." The compromised data includes names, email addresses, phone numbers, and physical addresses. Furthermore, the breach extended to Framework for Business customers, potentially exposing company names, VAT and EIN numbers, billing email addresses, and business phone numbers.
The Risk of Third-Party Dependencies
Framework is a startup recognized for its commitment to repairability and modular hardware, but this incident highlights a common vulnerability in modern software architecture: the third-party supply chain. To handle its backend analytics and business data, Framework relied on Metabase's cloud-hosted instance. Because the intrusion happened through the vendor's infrastructure rather than Framework's own internal systems, the laptop maker had limited ability to prevent the initial access.
Why Upstream Attacks Matter
This incident underscores the critical risk of "upstream" or supply-chain attacks, where a company's security posture is only as strong as its least secure trusted vendor. The use of a zero-day vulnerability—a flaw unknown to the software vendor at the time of the attack—means there was no existing patch available to block the intrusion. This demonstrates that even companies with rigorous internal security protocols remain vulnerable to flaws embedded in outsourced analytics and backend tools.
Next Steps for Users
While payment information was not compromised, the theft of physical addresses and phone numbers increases the risk of targeted phishing and social engineering attacks against Framework users. Customers are advised to remain vigilant regarding unsolicited communications. Framework continues to coordinate with its vendors to ensure the vulnerability is fully mitigated and to assess the full scope of the data exfiltration.