Framework, the maker of modular, repairable laptops, has begun informing every customer that their personal information—names, email addresses, phone numbers, and physical addresses—was stolen in a cyberattack. The breach originated not at Framework itself, but at Metabase, a third-party business intelligence provider whose cloud servers were compromised. Main Developments Social media posts from customers on Thursday confirmed that notification emails had arrived, with Framework spokesperson Eric Schumacher telling TechCrunch that "all customers" were affected. While the company declined to provide a specific number of impacted individuals, industry estimates suggest Framework has sold hundreds of thousands of devices, making the scope potentially significant. Read also: Offshore Wind Cancellations Cost U.S. Nearly $4 Billion Framework's notification, reviewed by TechCrunch, attributes the incident to an "upstream cyberattack" at Metabase. The attached email from Metabase explains that hackers exploited an unknown security flaw—a zero-day vulnerability—to gain access to customer databases stored on Metabase's cloud infrastructure. Framework's own investigation confirmed that stolen data included personal details but notably excluded payment information. Metabase has not yet responded to requests for comment on the incident. Background Metabase disclosed its own breach in a blog post on its official website, acknowledging the zero-day exploit that allowed unauthorized access to its cloud servers. Framework, known for its repairable and upgradeable computer designs, relies on various third-party vendors for business operations, and this incident highlights the supply-chain risk inherent in such dependencies. Why It Matters For Framework's customer base—which skews toward privacy-conscious and technically savvy users—this breach is particularly concerning. The exposure of physical addresses and phone numbers, combined with the fact that the attack came through an upstream vendor, underscores how even security-focused companies can be vulnerable to third-party failures. The absence of payment data offers some relief, but the stolen personal information remains valuable for phishing and identity-theft schemes. What's Next Framework has not announced any additional security measures or compensation plans beyond the notification. Affected customers will likely need to remain vigilant for phishing attempts leveraging their exposed data. Metabase, meanwhile, faces pressure to disclose technical details of the zero-day and any remediation steps, though no timeline for such disclosures has been provided.