[launches] · · 1 min read
Framework data breach exposes customer data via Metabase zero-day
Framework, the modular laptop maker, notified all customers that a breach at analytics vendor Metabase exposed names, emails, phone numbers, and addresses.
By ByteBulletin Editors · Editorial Team
Framework, the company known for its modular, repairable laptops, has notified all of its customers that their personal information was stolen in a data breach. The attack originated not at Framework itself, but at Metabase, a business intelligence vendor that Framework uses. On Thursday, several customers reported receiving breach notification emails, and a Framework spokesperson confirmed the incident.
The stolen data includes names, email addresses, phone numbers, and physical addresses—but not payment information. Metabase disclosed its own breach in a blog post, saying hackers exploited an unknown zero-day vulnerability to access customers' databases on Metabase's cloud servers. Framework's notification included a copy of Metabase's email, which stated that the hacker accessed Framework's cloud instance.
Framework has not disclosed the number of affected customers, but estimates suggest the company has sold hundreds of thousands of devices. The breach is a reminder that even companies with strong security postures can be compromised through third-party vendors.
For developers and tech enthusiasts, this incident highlights the growing risk of supply-chain attacks. When you integrate a tool like Metabase into your stack, you're not just trusting that vendor—you're trusting their entire security infrastructure. Zero-day exploits in widely used open-source tools are particularly dangerous, as they can be weaponized before patches are available.
Framework customers should be on the lookout for phishing emails, as their contact information is now in the hands of attackers. If you've received a notification, change your passwords and enable two-factor authentication where possible. Also, be wary of unsolicited messages that reference your Framework order or personal details.
As for Metabase, the company has not responded to requests for comment, but users of Metabase Cloud should check for updates and consider rotating any credentials that may have been exposed.
SOURCES
SHARE
RELATED

[launches] ·
Mixar launches AI-native Blender workspaces with purpose-built workbenches
Mixar's new browser-based tool rethinks Blender with task-specific rooms for texturing, UV mapping, and modeling, each tuned for AI-assisted workflows.

[launches] ·
OpenAI Fires Back at Apple's Trade Secrets Lawsuit with Public 'Receipts'
The ChatGPT maker publishes messages and emails to counter Apple's allegations of stolen trade secrets and to sway public opinion.

[launches] ·
Roblox agrees to third-party child safety audits after Australian regulator finds gaps
Australia's eSafety regulator has forced Roblox into a court-enforceable agreement to strengthen child safety measures and submit to independent audits.