A hacker breached upgradable laptop maker Framework Computer and accessed a customer database. The San Francisco PC maker began notifying customers on Thursday, saying the breach exposed “customer names, email addresses, phone numbers, and [shipping] addresses,” but not order or payment information.
The breach occurred through a third-party company called Metabase, which uses AI to deliver “business intelligence” to its 100,000+ clients, which seem to include McDonalds, T-Mobile and Hugging Face.
The hacker used a previously unknown “zero-day” vulnerability in the Metabase Cloud system affecting versions 1.58 and above. “We also discovered that the attacker was able to gain access to your instance,” Metabase told Framework on Thursday morning.
Framework has been reviewing the logs provided by Metabase, and they show that the hacker accessed data on customer login IP addresses and full billing and shipping addresses. For business customers, Framework is still determining whether the company name, phone number, and billing email were exposed.
In the meantime, the PC maker said that “No other personally identifiable information, order information, or payment information was accessed.” It’s unclear whether the attacker downloaded all the exposed data. Still, a Framework spokesperson tells PCMag the breach affects all customers. Metabase’s own investigation remains ongoing, so it’s possible that more data and corporate clients were affected.
Recommended by Our Editors
Your Data Was Leaked. Here’s What Hackers Hope You Don’t Do Next
Suspected Chinese Hackers Compromised This VPN to Deliver Malware
52% of Americans Think Their Personal Data Will Be Breached. They’re Probably Right
In response, Framework says it “rotated credentials on all databases associated with our Metabase instance and confirmed that there were no changes in admin access or access to systems outside of Metabase.” Metabase <a href="https://www.metabase.com/blog/security-update” rel=”nofollow noopener” target=”_blank”>says it’s already patched the zero-day vulnerability.
In January 2024, Framework also reported a breach involving a third-party accounting firm, Keating Consulting, that exposed customer names and email addresses.
About Our Expert
Michael Kan
Principal Reporter
Experience
I’ve been a journalist for over 15 years. I got my start as a schools and cities reporter in Kansas City and joined PCMag in 2017, where I cover satellite internet services, cybersecurity, PC hardware, and more. I’m currently based in San Francisco, but previously spent over five years in China, covering the country’s technology sector.
Since 2020, I’ve covered the launch and explosive growth of SpaceX’s Starlink satellite internet service, writing 600+ stories on availability and feature launches, but also the regulatory battles over the expansion of satellite constellations, fights with rival providers like AST SpaceMobile and Amazon, and the effort to expand into satellite-based mobile service. I’ve combed through FCC filings for the latest news and driven to remote corners of California to test Starlink’s cellular service.
I also cover cyber threats, from ransomware gangs to the emergence of AI-based malware. In 2024 and 2025, the FTC forced Avast to pay consumers $16.5 million for secretly harvesting and selling their personal information to third-party clients, as revealed in my joint investigation with Motherboard.
I also cover the PC graphics card market. Pandemic-era shortages led me to camp out in front of a Best Buy to get an RTX 3000. I’m now following how the AI-driven memory shortage is impacting the entire consumer electronics market. I’m always eager to learn more, so please jump in the comments with feedback and send me tips.
Areas of Expertise
Latest By Michael Kan
- If Orbital Data Centers Take Off, Brace For Giant Rings In The Night Sky
- Starlink Revives Optional Mini Kit Perk for Residential Max Plan
- Higher Costs, Insecure Software? How US Ban on Foreign Inverters Could Hit Solar
- Environmental Groups Want FCC to Reverse Plans for Space Mirror Satellite
- 20 Wi-Fi Routers From This Chinese Vendor Found With a Backdoor
- More from Michael Kan
