Framework, a manufacturer of modular repairable computers, has alerted its entire customer base following a significant data breach. The company confirmed that hackers gained unauthorized access to customer names, email addresses, phone numbers, and physical addresses through a security incident at a third-party vendor.
The breach originated from a cyberattack on Metabase, a business intelligence platform that Framework relied upon to store customer information. According to Metabase’s own disclosure, attackers exploited a previously unknown security vulnerability to gain access to customer databases hosted on the company’s cloud infrastructure. Framework’s spokesperson Eric Schumacher confirmed that the breach affected all customers, though he declined to provide a specific number of affected individuals. Industry estimates suggest the company has sold hundreds of thousands of devices.
In its notification to customers, Framework confirmed that the stolen data did not include payment information or financial details. The company stated it had completed its investigation into the incident and determined the full scope of the breach. Metabase has not yet responded to requests for additional comment regarding the security incident and its response measures.