Framework, a modular laptop company, says it suffers a data breach after attackers exploit a zero-day vulnerability in Metabase, the business intelligence service Framework uses. In customer notifications, the company states the attackers gain access to specific account-related information.

According to Framework, the exposed data includes customers’ names, email addresses, phone numbers, and physical addresses, along with login IP addresses. Both reports say payment information and order-related records are not accessed or are not affected. After the incident, Framework rotates credentials and Metabase patches the underlying vulnerability. A forensic investigation is also ongoing, as described by one outlet.

The coverage focuses on what data is accessed versus what is not, and on the response steps taken. One report emphasizes the zero-day exploitation pathway, while the other highlights practical guidance for customers and the status of remediation and investigation. Both accounts attribute the compromise to Metabase and describe limited scope of the stolen information.