Framework alerts customers after Metabase cloud breach

Framework, the maker of modular and repairable computers, has notified all of its customers that personal data was stolen after attackers accessed its cloud instance at business-intelligence provider Metabase. The affected information includes names, email addresses, phone numbers and physical addresses. Framework said payment information was not included.
Several customers reported receiving the notification email on social media on Thursday. Framework spokesperson Eric Schumacher told TechCrunch that the incident affected “all customers,” while declining to provide a specific number. Framework products serve a relatively niche market, although estimates cited in the report put device sales in the hundreds of thousands.
An upstream compromise reached Framework data
Framework attributed the incident to a cyberattack affecting Metabase. In its notification, the computer maker included the message it received from Metabase, which stated that attackers had accessed Framework’s cloud instance.
Metabase said in a post on its official website that an attacker used an unknown security flaw, described as a zero-day, to compromise its environment. The company said exploitation of the vulnerability gave the attacker the ability to access customer databases stored on Metabase cloud servers.
Framework said it investigated the incident after learning of the Metabase compromise and determined that customer personal data had been taken. The company’s disclosure distinguishes those contact and address records from payment information, which it said was not part of the exposed data.
Third-party data systems extend breach exposure
The incident illustrates how a supplier handling business intelligence can become part of a company’s customer-data exposure. A cloud service used outside a core transactional system may still contain enough personal information to create a significant notification obligation when it is compromised.
For organizations, the practical implication is to map which vendors store customer records and which fields each service can access. Limiting sensitive data in third-party analytics environments, reviewing provider incident communications and maintaining a tested notification process can help teams respond when an upstream compromise affects their own customers.

