Framework Notifies Customers of Data Incident via Metabase: What Was Reportedly Exposed & What To Do
Framework disclosed on August 06, 2026 that it experienced a data incident affecting all customers, which occurred on August 03, 2026. Anyone who has an account with the company should review the notice and take any recommended steps to protect their information.
Business-intelligence platforms have become a recurring pressure point in the current threat landscape: when analytics tools sit close to live customer records, a single unpatched flaw can expose personal data at scale. Framework, the computer manufacturer, has now confirmed that pattern in its own environment.
On August 6, 2026, Framework emailed all customers to report unauthorized access to names, email addresses, phone numbers and physical addresses. The access stemmed from a zero-day vulnerability exploited in the company’s Metabase business-intelligence instance. Metabase itself disclosed a cloud attack and released a security update the same day; Framework began notifications immediately. Payment details and sensitive order data were not accessed. The incident matters because the exposed identifiers are durable and useful for fraud and social engineering long after the technical event ends.
Inside the incident
According to Framework’s customer notice, attackers gained unauthorized access to customer contact information held in or reachable through its Metabase instance. The company attributed the access to exploitation of a zero-day vulnerability in Metabase. Metabase publicly disclosed the cloud attack and issued a security update on August 6, 2026; Framework started notifying every customer that same day.
The notice states that the exposed data types were names, email addresses, phone numbers and physical addresses, and that the population affected was all customers. It also states that no payment or sensitive order data was accessed. Public detail does not describe the exact access method used against the zero-day, whether the Metabase instance was directly internet-facing, or what compensating controls, if any, were in place at the time. Those points remain undisclosed.
How a breach like this happens
Incidents of this type typically begin when a business-intelligence or analytics platform is granted broad read access to production customer data so that dashboards and reports stay current. If that platform is reachable from outside the most tightly controlled network zones, or if it is not promptly patched when a critical flaw appears, an attacker who obtains a working exploit can query or export the connected datasets.
Zero-day vulnerabilities are especially dangerous because no vendor patch yet exists at the moment of exploitation. Even after a patch is released, organizations must still apply it and verify that any temporary exposure has been contained. Industry experience shows that analytics tools repeatedly become high-risk surfaces when they sit on the same logical path as live personally identifiable information without strong network segmentation, strict allow-listing, or other isolation controls. No specific threat group has been attributed in the Framework disclosure, and none is asserted here.
Who is Framework?
Framework is a computer manufacturer known for modular laptops and related hardware sold directly to consumers and professionals. Like other direct-to-consumer hardware companies, it maintains customer accounts, shipping and billing contact records, and support histories in order to fulfill orders, provide warranty service and communicate product updates.
A breach at a manufacturer of this kind is consequential because the customer base is broad and the contact data is both accurate and relatively stable. Physical addresses and phone numbers tied to real names support targeted phishing, account-recovery abuse and, in some cases, physical-world risks that do not disappear when a password is changed. The company’s reliance on a business-intelligence tool with access to that data made the analytics layer a high-value target once a zero-day became available.
What data was at risk
Framework’s notice names the exposed data types explicitly: names, email addresses, phone numbers and physical addresses. It further states that payment information and sensitive order data were not accessed. No other categories—such as passwords, government identifiers or full financial account numbers—are described as exposed in the disclosure, and none should be assumed.
Organizations in this sector typically also hold order histories, serial numbers and support correspondence. Whether any of those additional elements were reachable through the Metabase instance is unconfirmed; the company has only confirmed the four contact fields listed above. Readers should treat only the named data types as established fact.
The real-world impact
For affected individuals, the practical risks are long-lived. Legal names combined with home addresses and phone numbers enable convincing phishing and smishing campaigns, fraudulent account-recovery attempts at other services, and secondary identity-theft activity that can surface months or years later. Physical addresses also raise the possibility of unwanted mail or, in rarer cases, in-person targeting. Because these identifiers do not expire the way a password reset does, the exposure window is extended.
For Framework, the incident creates notification obligations, potential regulatory scrutiny, and the operational cost of investigating scope, hardening the analytics environment and supporting customers. The company has stated that payment and sensitive order data were not reached, which limits certain classes of immediate financial fraud, yet the confirmed contact data alone is sufficient to generate lasting customer concern and support volume.
Were you affected?
Framework has stated that all customers were notified. If you have ever purchased from or registered with Framework, treat the notice as applying to you unless the company later narrows the scope. Practical first steps include: treat unexpected emails, texts or calls that reference your Framework purchase or address with heightened skepticism; verify any request for personal or payment information through official channels you initiate yourself; monitor financial and account-recovery activity for unusual attempts; and consider placing a fraud alert or credit freeze if you routinely reuse contact details across services.
You can also run a free exposure scan of your email address to check whether that address has already appeared in other known breach datasets. Doing so does not reverse the Framework incident, but it helps you see whether the same address is circulating more widely and prioritize further monitoring.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Nextcloud Misconfiguration Exposes 367K Staff and Client RecordsUniversity of Nottingham Data Breach (2026)Grindr Users' Data Allegedly Leaked on Cybercrime ForumZara Data Breach (2026)Latest breaches
Based on public reporting
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.