Framework, the maker of modular, repairable computers, has notified all of its customers of a data breach. In an email sent on Thursday, the company confirmed that hackers accessed customers' names, email addresses, phone numbers, and physical addresses. Framework spokesperson Eric Schumacher told TechCrunch that the breach affected "all customers," declining to give a specific number — though market estimates suggest the company has sold hundreds of thousands of devices.
The most important detail is where the problem started. Framework attributed the breach to a security incident at Metabase, a business intelligence company that provides data analytics tools. According to BleepingComputer, the attack exploited a zero-day SQL injection (SQLi) vulnerability in Metabase, which is already being used in data-theft attacks against multiple organizations. Framework was one of those affected, but not the only one: Tally also confirmed it was hit by the same vector.
This kind of supply-chain attack is particularly nasty because it shifts the blame. The end customer — in this case, the Framework buyer — did nothing wrong, but their information leaked because a third-party supplier was compromised. It is the same pattern seen in other famous breaches, such as when an attacker compromised a ticketing system and exposed millions of passengers, or when an HR software vendor leaked data from hundreds of companies at once. Framework even forwarded Metabase's own breach notification to customers, an unusual step that underscores the effort to be transparent about where the problem began.
For a company that has built its brand around right-to-repair, modularity, and user trust, this breach is a double blow. Framework does not just sell laptops; it sells a philosophy of ownership and transparency, and this incident strikes directly at the trust pillar. The leaked data — names, emails, phones, and addresses — is exactly the kind of information that feeds phishing campaigns, SIM swapping, and even identity theft, meaning customers will need to stay vigilant for months.
There is also a broader lesson about the economics of security in niche companies. A firm with hundreds of thousands of customers does not have the security budget of a giant like Apple or Microsoft, and it depends on suppliers whose level of protection is beyond its direct control. The open question is how many other mid-sized companies are exposed to this same kind of attack without knowing it. When a single analytics software vendor can shake the trust of an entire brand, the risk of outsourcing stops being purely technical — it becomes a strategic survival question.
For affected customers, the advice is the usual but no less important: be wary of calls and messages that cite personal data, change passwords, and enable two-factor authentication where possible. For the industry, the lesson is that a company's security perimeter does not end at its own servers — it extends to every supplier that touches customer data. Whoever outsources data analytics, payments, or any critical service needs to demand from partners the same level of auditing it would apply internally, or it will always be one step behind whoever finds the gap in the chain.
Sources: TechCrunch, BleepingComputer, Engadget
✓ Independent sources cross-checked and verified before publishing