Home / Technology

Photo of circuit board, laptop, processor chip
Image: Wikipedia
Technology

Modular PC Maker Framework Warns All Customers of Third-Party Data Breach

WireByte Staff · August 7, 2026

Modular computer manufacturer Framework has alerted all customers that hackers stole their personal information, including names, addresses, and phone numbers. The incident stemmed from a cyberattack on its business intelligence provider, Metabase, which suffered a zero-day exploit on August 3, 2026. Framework confirmed that payment details remained secure and that it has since rotated its credentials.

Key points

  • Framework, a manufacturer of modular and repairable computers, notified its entire customer base on August 6, 2026, regarding a major data breach.
  • Hackers accessed customer names, email addresses, phone numbers, login IP addresses, and physical addresses via an upstream vendor.
  • The breach originated from an unknown zero-day vulnerability exploited at Metabase, the cloud-based business intelligence provider utilized by Framework.
  • Both companies confirmed that sensitive financial details, including customer payment information, were not exposed in the security incident.
  • Following the intrusion, Framework rotated its security credentials, investigated its cloud instance, and announced reviews of its external data storage methods.

Modular computer maker Framework has issued a security notification to its entire customer base following a cyberattack that compromised personal user data. According to communications sent by the company, malicious actors accessed customer names, physical addresses, phone numbers, email addresses, and login IP addresses. Although the company declined to disclose the exact count of affected individuals, industry estimates suggest the niche hardware manufacturer has sold hundreds of thousands of devices globally.

The intrusion was not the result of a direct compromise of Framework's internal infrastructure, but rather an upstream security failure at Metabase, a cloud-based business intelligence provider used by the hardware company. Metabase disclosed that an unknown zero-day vulnerability was exploited to breach customer databases hosted on its servers. Metabase identified the intrusion on August 3, 2026, subsequently patching the flaw and engaging a third-party forensic investigation firm to examine the full scope of the incident.

In response to the breach, Framework stated that it immediately rotated its administrative credentials and verified that unauthorized access remained isolated to the Metabase cloud instance, with no broader penetration of internal company systems. The company assured customers that financial details were excluded from the exposed data, as payment information is handled separately. Framework is now reviewing its data storage methodologies concerning external database vendors to prevent similar supply-chain incidents.

Sources

WireByte Staff — Editorial Team

The WireByte editorial team synthesises technology news from multiple primary sources, verifies the facts, and links every source. Articles are produced with AI assistance and reviewed under our editorial policy.