Framework’s customer data stolen in a third-party breach you probably didn’t see coming

Framework built its reputation on transparency. So when every single one of its customers got an email this week saying their personal data had been stolen, at least the company told them. That’s a low bar, but in this industry, it still counts for something.

According to TechCrunch, Framework confirmed the breach affects all of its customers. Company spokesperson Eric Schumacher declined to give a specific number, but Framework has sold an estimated hundreds of thousands of devices. The exposed data includes names, email addresses, phone numbers, and physical addresses. Payment information was reportedly not included, which is something, but your home address sitting in a hacker’s database is not exactly a comfortable thought either.

The breach didn’t start at Framework. It started at Metabase, a business intelligence company that Framework used to manage cloud-hosted data. Metabase was hit by a zero-day exploit, meaning an attacker used a security flaw that had no patch available at the time. That gave the hacker access to customer databases stored on Metabase’s cloud servers, including the data Framework had there. Metabase disclosed the breach on its own blog but did not respond to a request for comment from TechCrunch.

This is the part that should make anyone uncomfortable. Framework didn’t fail to encrypt something or leave a server exposed. It trusted a third party, that third party got hit, and now Framework’s customers are the ones dealing with the fallout. That’s the reality of modern software supply chains. Every vendor you use is a potential attack surface, and most companies have no real visibility into how secure those vendors actually are.

The stolen data is the kind that fuels phishing campaigns, SIM swapping, and targeted scams. Names paired with addresses and phone numbers is a useful package for anyone trying to impersonate you or trick someone close to you. Framework customers, who tend to be technically minded people willing to pay a premium for a repairable laptop, are exactly the type of targets that more sophisticated attackers find worthwhile.

Framework did include Metabase’s original breach notification in its email to customers, which at least shows its hand rather than burying the blame. But transparency after the fact only goes so far. The bigger question is what due diligence Framework, or any hardware company, actually does before handing customer data to a third-party analytics platform. That answer, in most cases, is not enough.