Laptop Maker Framework Says Hackers Got Customer Data Through Another Company's Breach

Computer maker Framework told all of its customers on August 7, 2026, that hackers stole personal data including names, email addresses, phone numbers, and physical addresses. The company said the breach happened because another company it works with, called Metabase, was hacked. Payment information was not stolen. TechCrunch
Framework spokesperson Eric Schumacher confirmed to TechCrunch that the breach affected "all customers" but would not say how many people that includes. Customers started posting on social media on Thursday, August 6, that they had received emails from the company. Framework's email to customers included a copy of the alert that Metabase had sent to Framework, saying that hackers had gotten into Framework's cloud account. TechCrunch
Metabase explained the breach in a blog post on its website, saying that a hacker found and exploited a security flaw that nobody knew about yet. This kind of flaw is called a zero-day vulnerability because the software maker has had zero days to fix it before attackers use it. The attackers used the bug to reach customer databases stored on Metabase's own servers. Metabase did not respond to a request for comment from TechCrunch. TechCrunch; Metabase
This is the second known data breach to hit Framework customers. In January 2024, the company said that hackers got customer names and email addresses after tricking an employee at Keating Accounting, an outside firm that handles Framework's accounting. That earlier breach involved less information, only names and email addresses, while this one also includes phone numbers and home addresses. TechCrunch; PC Magazine
The problem here is a common one in the technology world: when a company hands its data to another company's service, that data is only as safe as the other company's security. Framework's own systems were not hacked. Instead, the attack went through Metabase, a tool Framework uses to analyze its data. Metabase connects directly to customer databases, so when hackers broke into Metabase, they could reach the customer information Framework had stored there.
The broader context is that tools like Metabase are most useful when they have access to a lot of data, but that same wide access means a single break-in can expose everything. Framework has now had two breaches in under three years, each through a different outside company. Framework itself was not the direct target in either case, but its customer data was what the attackers ultimately got.
In my view, many companies do not pay enough attention to the security of the outside tools they use to analyze or manage customer data. When one of those tools is hacked, the damage depends on what data the company has connected to it. Framework appears to have connected enough personal information to its Metabase account to expose its entire customer list. The fact that phone numbers and home addresses were included makes the risk worse, because attackers can use that information for highly targeted scams and impersonation.
One thing worth noting is how Framework handled the disclosure. The company forwarded Metabase's internal warning directly to its customers, rather than rewriting it into a polished corporate statement. That gave customers the raw details of what went wrong. Metabase, by contrast, posted about the flaw on its blog but did not respond to questions from reporters, leaving a gap between what it told its customers and what it has told the public.
For Framework customers, the practical steps are simple: be extra cautious about any message that references your personal account details, turn on two-step verification on your Framework account if it is available, and watch for scam attempts that use your exposed phone number or address. For everyone else, this is a reminder that when you give your data to a company, that company may share it with other services whose security you have no way to evaluate.


