Framework Notifies All Customers of Data Breach via Metabase Zero-Day

Computer maker Framework notified its entire customer base on August 7, 2026, that hackers stole personal data including names, email addresses, phone numbers, and physical addresses in a data breach. The company attributed the incident to an upstream cyberattack at Metabase, the business intelligence provider that hosts Framework's cloud analytics instance. Payment information was not compromised. TechCrunch
Framework spokesperson Eric Schumacher confirmed to TechCrunch that the breach affected "all customers" but declined to specify the total number of individuals impacted. Customers began reporting on social media on Thursday, August 6, that they had received notification emails from the company. Framework's notification included a forwarded copy of the alert Metabase sent to Framework, which stated that hackers had accessed Framework's cloud instance. TechCrunch
Metabase disclosed its own breach in a blog post on its official website, stating it was hacked by an actor exploiting an unknown security flaw, a zero-day vulnerability. The attackers used the bug to gain access to customer databases stored on Metabase's cloud servers. Metabase did not respond to a request for comment from TechCrunch regarding the incident. TechCrunch; Metabase
This is the second known data breach to affect Framework customers. In January 2024, the company confirmed that hackers accessed customer names and email addresses after successfully phishing an employee at Keating Accounting, Framework's external accounting partner. That earlier incident exposed a narrower set of data fields, limited to names and email addresses, compared to the current breach which also includes phone numbers and physical home addresses. TechCrunch; PC Magazine
The incident illustrates a recurring supply-chain risk in cloud-dependent enterprise architectures. Framework's primary failure point was not its own infrastructure but a third-party SaaS vendor with privileged access to customer data stores. Metabase, widely used for embedded analytics and internal dashboards, sits in a particularly sensitive position: its cloud instances connect directly to production databases, often with read access to broad schemas. A zero-day in that layer can bypass the application-level access controls a company like Framework configures, handing attackers a direct pipe to underlying records.
In this author's view, the reliance on third-party business intelligence tools presents an attack surface that many organizations underweight in their vendor risk assessments. When a BI tool is compromised, the blast radius is determined not by the vendor's own data but by the schemas and tables the customer has connected to that vendor's platform. Framework appears to have connected enough personally identifiable information to its Metabase instance to expose its full customer roster. The inclusion of physical addresses and phone numbers significantly raises the phishing and social engineering risk for affected individuals, as it enables highly targeted offline attacks and convincing impersonation schemes.
Worth flagging is the pace and transparency of the disclosure. Framework forwarded Metabase's internal alert directly to customers, a move that sidesteps corporate sanitization and gives affected individuals the raw context of the upstream failure. Metabase's silence in response to press inquiries contrasts with its public blog post acknowledging the zero-day, leaving a gap between what the vendor has told its direct customers and what it has told the public.
The broader context here is the tension between operational convenience and data minimization. BI tools are most useful when connected to rich, wide data sets, but that same breadth turns a single vendor compromise into a full customer exfiltration event. Framework has now experienced two distinct vendor-mediated breaches in under three years, each through a different third party. While the company itself was not the direct target of the phishing or the zero-day exploit, its customer data was the ultimate payload in both cases.
For Framework's customers, the immediate practical steps are straightforward: treat any communication referencing personal account details with heightened suspicion, enable multi-factor authentication on Framework accounts where available, and monitor for targeted phishing attempts that leverage the exposed phone numbers and addresses. For the wider technology community, the incident is a reminder that data shared with a vendor is only as secure as that vendor's least-tested code path.


