via TechCrunch
Framework Notifies 'All Customers' of Data Breach Linked to Upstream Vendor Incident
Framework, the company known for its modular and repairable laptops, has alerted all of its customers that hackers accessed their names, email addresses, phone numbers, and physical addresses. The breach stemmed from a security incident at Metabase, a third-party business intelligence provider, as reported by TechCrunch.
On Thursday, several Framework customers took to social media—including posts on X and Reddit—to share notifications they received from the company regarding the breach. Framework's spokesperson, Eric Schumacher, confirmed to TechCrunch that the incident affected "all customers," though he declined to provide a specific number. While Framework's products occupy a niche market, some estimates suggest the company has sold hundreds of thousands of devices.
According to the notification reviewed by TechCrunch, the company attributes the breach to an upstream cyberattack on Metabase. In a blog post on its official website, Metabase disclosed that it was compromised by an attacker exploiting an unknown security flaw—a zero-day vulnerability—which allowed unauthorized access to customer databases stored on its cloud servers.
Framework's email to customers included a copy of Metabase's notification, which revealed that hackers had accessed Framework's cloud instance. Following an internal investigation, Framework confirmed that the stolen data included customers' personal information but noted that payment details were not compromised.
As of this writing, Metabase has not responded to requests for comment. This incident underscores the growing risks associated with third-party vendors and the importance of robust supply chain security in the tech industry.
