"We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors," Framework wrote in an email to customers after a zero‑day in analytics provider Metabase exposed personal data, the laptop maker said.
How Metabase says the attacker got in
Metabase told customers and operators that an attacker targeted its cloud service by exploiting a previously unknown vulnerability affecting versions 1.58 and later. The company said it blocked the endpoints used in the attack, patched the bug, and deployed the fix across its cloud service.
According to Metabase, exploitation can allow an attacker to inject arbitrary SQL against the application's database and potentially gain administrator access. From there, an attacker could "alter configuration settings, steal credentials for databases connected to Metabase, query data those connections can access, and export the results," the vendor said. Metabase advised anyone running their own instance to patch immediately.
What customer data Framework says was exposed
Framework warned that the intruder accessed names, email addresses, phone numbers, physical addresses, and login IP addresses. For business customers, the exposed information may also include company names, phone numbers, VAT or Employer Identification Numbers (EINs), and billing email addresses.
Framework explicitly said order and payment details were not affected. The company told TechCrunch the breach had affected "all customers," and said it is notifying regulators where required — while noting that "names, email addresses, phone numbers, and physical addresses don't cross the mandatory reporting threshold in many regions." Regardless, Framework said it is notifying customers directly.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildTimeline: discovery, notification, and initial containment
Metabase discovered the attack on August 3 and notified Framework at 9 a.m. Pacific Time on August 6, telling the laptop maker that its instance had been vulnerable and that the attacker had successfully gained access to it. Framework said it then rotated credentials for every database connected to its Metabase instance.
The company reported that after those rotations it had found "no changes to admin access" and "no evidence that systems outside Metabase had been accessed." Framework has retained a third‑party forensics firm to investigate the incident, and cautioned that the firm's findings so far are preliminary.
Framework's stated next steps and recent company context
Framework said it is "reviewing and improving our methodology for data storage in external database vendors" but has not yet detailed what concrete changes that review might produce. The company told The Register it is deeply sorry for the breach and is notifying regulators where required.
The incident arrives against a backdrop of operational pressures Framework disclosed in July: the company warned that the price it was being charged for LPCAMM2 memory used in its Laptop 13 Pro had more than doubled, forcing a memory price increase, and that CPU prices were also rising and could push overall system prices higher in coming weeks.
What this means for technologists, business customers, and end users
- Technologists and security teams: Metabase's advisory lists specific remediation tasks for administrators — patch vulnerable installations, block or fix exploited endpoints, rotate database credentials, kill active sessions if a vulnerable password‑reset endpoint was exposed, look for rogue API keys or admin accounts, and review logs for suspicious activity.
- Business customers and procurement leaders: Firms that use Framework for purchases should expect notification and may need to review exposure of company names, phone numbers, VAT or EIN identifiers, and billing email addresses. Framework says order and payment details were not affected.
- End users and the general public: Individuals should know that names, email addresses, phone numbers, physical addresses and login IP addresses were exposed; Framework is notifying customers directly despite noting those fields may fall below mandatory breach‑reporting thresholds in some regions.
Framework has rotated connected database credentials and engaged outside forensic help, and Metabase has patched and rolled out a fix across its cloud service. The immediate technical vectors and initial containment actions are documented; what remains to be seen is the concrete set of policy or architecture changes Framework will make to limit customer data exposure through third‑party analytics providers. The Register summed the tradeoff crisply: "Being able to replace almost every part of your laptop is handy. Finding your home address exposed through an analytics service is rather less so."




