Skip to content
Upgradable Laptop Maker Framework Suffers Breach Affecting All Customers

Upgradable Laptop Maker Framework Suffers Breach Affecting All Customers

Uk.Pcmag • August 7, 2026

A hacker breached upgradable laptop maker Framework Computer and accessed a customer database. The San Francisco PC maker began notifying customers on Thursday, saying the breach exposed “customer names, email addresses, phone numbers, and [shipping] addresses,” but not order or payment information. The breach occurred through a third-party company called Metabase, which uses AI to deliver “business intelligence” to its 100,000+ clients, which seem to include McDonalds, T-Mobile and Hugging Face. The hacker used a previously unknown “ zero-day ” vulnerability in the Metabase Cloud system affecting versions 1.58 and above. “We also discovered that the attacker was able to gain access to your instance,” Metabase told Framework on Thursday morning. Framework has been reviewing the logs provided by Metabase, and they show that the hacker accessed data on customer login IP addresses and full billing and shipping addresses. For business customers, Framework is still determining whether the company name, phone number, and billing email were exposed. In the meantime, the PC maker said that “No other personally identifiable information, order information, or payment information was accessed.” It's unclear whether the attacker downloaded all the exposed data. Still, a Framework spokesperson tells PCMag the breach affects all customers. Metabase’s own investigation remains ongoing, so it's possible that more data and corporate clients were affected. In response, Framework says it “rotated credentials on all databases associated with our Metabase instance and confirmed that there were no changes in admin access or access to systems outside of Metabase.” Metabase says it's already patched the zero-day vulnerability. In January 2024, Framework also reported a breach involving a third-party accounting firm, Keating Consulting, that exposed customer names and email addresses.

The breach occurred through a third-party company called Metabase, which uses AI to deliver “business intelligence” to its 100,000+ clients, which seem to include McDonalds, T-Mobile and Hugging Face. The hacker used a previously unknown “ zero-day ” vulnerability in the Metabase Cloud system affecting versions 1.58 and above. “We also discovered that the attacker was able to gain access to your instance,” Metabase told Framework on Thursday morning. Framework has been reviewing the logs provided by Metabase, and they show that the hacker accessed data on customer login IP addresses and full billing and shipping addresses. For business customers, Framework is still determining whether the company name, phone number, and billing email were exposed. In the meantime, the PC maker said that “No other personally identifiable information, order information, or payment information was accessed.” It's unclear whether the attacker downloaded all the exposed data. Still, a Framework spokesperson tells PCMag the breach affects all customers. Metabase’s own investigation remains ongoing, so it's possible that more data and corporate clients were affected. In response, Framework says it “rotated credentials on all databases associated with our Metabase instance and confirmed that there were no changes in admin access or access to systems outside of Metabase.” Metabase says it's already patched the zero-day vulnerability. In January 2024, Framework also reported a breach involving a third-party accounting firm, Keating Consulting, that exposed customer names and email addresses.

The hacker used a previously unknown “ zero-day ” vulnerability in the Metabase Cloud system affecting versions 1.58 and above. “We also discovered that the attacker was able to gain access to your instance,” Metabase told Framework on Thursday morning. Framework has been reviewing the logs provided by Metabase, and they show that the hacker accessed data on customer login IP addresses and full billing and shipping addresses. For business customers, Framework is still determining whether the company name, phone number, and billing email were exposed. In the meantime, the PC maker said that “No other personally identifiable information, order information, or payment information was accessed.” It's unclear whether the attacker downloaded all the exposed data. Still, a Framework spokesperson tells PCMag the breach affects all customers. Metabase’s own investigation remains ongoing, so it's possible that more data and corporate clients were affected. In response, Framework says it “rotated credentials on all databases associated with our Metabase instance and confirmed that there were no changes in admin access or access to systems outside of Metabase.” Metabase says it's already patched the zero-day vulnerability. In January 2024, Framework also reported a breach involving a third-party accounting firm, Keating Consulting, that exposed customer names and email addresses.

Framework has been reviewing the logs provided by Metabase, and they show that the hacker accessed data on customer login IP addresses and full billing and shipping addresses. For business customers, Framework is still determining whether the company name, phone number, and billing email were exposed. In the meantime, the PC maker said that “No other personally identifiable information, order information, or payment information was accessed.” It's unclear whether the attacker downloaded all the exposed data. Still, a Framework spokesperson tells PCMag the breach affects all customers. Metabase’s own investigation remains ongoing, so it's possible that more data and corporate clients were affected. In response, Framework says it “rotated credentials on all databases associated with our Metabase instance and confirmed that there were no changes in admin access or access to systems outside of Metabase.” Metabase says it's already patched the zero-day vulnerability. In January 2024, Framework also reported a breach involving a third-party accounting firm, Keating Consulting, that exposed customer names and email addresses.

In the meantime, the PC maker said that “No other personally identifiable information, order information, or payment information was accessed.” It's unclear whether the attacker downloaded all the exposed data. Still, a Framework spokesperson tells PCMag the breach affects all customers. Metabase’s own investigation remains ongoing, so it's possible that more data and corporate clients were affected. In response, Framework says it “rotated credentials on all databases associated with our Metabase instance and confirmed that there were no changes in admin access or access to systems outside of Metabase.” Metabase says it's already patched the zero-day vulnerability. In January 2024, Framework also reported a breach involving a third-party accounting firm, Keating Consulting, that exposed customer names and email addresses.

In response, Framework says it “rotated credentials on all databases associated with our Metabase instance and confirmed that there were no changes in admin access or access to systems outside of Metabase.” Metabase says it's already patched the zero-day vulnerability. In January 2024, Framework also reported a breach involving a third-party accounting firm, Keating Consulting, that exposed customer names and email addresses.

In January 2024, Framework also reported a breach involving a third-party accounting firm, Keating Consulting, that exposed customer names and email addresses.

Extracted Entities