Framework Customer Data Exposed in Metabase Breach
Framework, the manufacturer of repairable and upgradeable laptops, has disclosed a data breach affecting all its customers. In an email sent on August 6, the company revealed that customer names, login IP addresses, physical addresses, phone numbers, and email addresses were accessed during a cyberattack on Metabase, its business database provider. Payment information was not compromised.
The breach occurred after an attacker exploited an unknown zero-day vulnerability in Metabase’s systems, which the provider detected on August 3. Metabase has since patched the flaw and is conducting a forensic investigation with a third-party firm to assess the full scope of the incident. The company’s findings remain preliminary.
Framework confirmed it rotated credentials following the breach and found no evidence of unauthorized admin access or compromise beyond Metabase’s systems. The company is now reviewing its data storage practices with external vendors to prevent future incidents.
The breach adds to Framework’s recent challenges, including supply chain disruptions and rising component costs. Earlier this year, the company raised prices twice due to memory shortages and was forced to reduce RAM in some preorders for its Framework Laptop Pro, offering full refunds to affected customers.
Metabase cybersecurity rating report: https://www.rankiteo.com/company/metabase
Framework cybersecurity rating report: https://www.rankiteo.com/company/frameworkcomputer
"id": "METFRA1786131154",
"linkid": "metabase, frameworkcomputer",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'All customers',
'industry': 'Technology (Laptop Manufacturing)',
'name': 'Framework',
'type': 'Company'}],
'attack_vector': 'Zero-day vulnerability exploitation',
'customer_advisories': 'Email sent to all customers on August 6, 2024',
'data_breach': {'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'Personally Identifiable Information '
'(PII)',
'type_of_data_compromised': ['Customer names',
'Login IP addresses',
'Physical addresses',
'Phone numbers',
'Email addresses']},
'date_detected': '2024-08-03',
'date_publicly_disclosed': '2024-08-06',
'description': 'Framework disclosed a data breach affecting all its customers '
'after an attacker exploited an unknown zero-day vulnerability '
'in Metabase, its business database provider. Customer names, '
'login IP addresses, physical addresses, phone numbers, and '
'email addresses were accessed. Payment information was not '
'compromised.',
'impact': {'data_compromised': 'Customer names, login IP addresses, physical '
'addresses, phone numbers, email addresses',
'identity_theft_risk': 'High',
'payment_information_risk': 'None',
'systems_affected': 'Metabase business database'},
'investigation_status': 'Ongoing (Preliminary findings)',
'post_incident_analysis': {'corrective_actions': 'Credential rotation, vendor '
'data storage review',
'root_causes': 'Zero-day vulnerability in '
'Metabase'},
'references': [{'date_accessed': '2024-08-06',
'source': 'Framework Customer Disclosure'}],
'response': {'communication_strategy': 'Email disclosure to customers',
'containment_measures': 'Rotated credentials, patched '
'vulnerability',
'remediation_measures': 'Reviewing data storage practices with '
'external vendors',
'third_party_assistance': 'Yes (Metabase engaged a third-party '
'forensic firm)'},
'title': 'Framework Customer Data Exposed in Metabase Breach',
'type': 'Data Breach',
'vulnerability_exploited': 'Unknown zero-day vulnerability in Metabase'}