Observed Signal · Aug 7, 2026 · Data Breach · Source: techcrunch · Impact: 1/5 · Sentiment: Negative

Framework notifies all customers of data breach

Executive Signal Summary

Framework, a maker of modular repairable computers, notified all customers that hackers accessed personal information — including names, email addresses, phone numbers and physical addresses — after an upstream cyberattack at business-intelligence provider Metabase. Framework said payment information was not included. Metabase disclosed it was hacked via an unknown security flaw (a zero-day) that allowed attackers access to customers' databases stored on its cloud servers. Framework's spokesperson Eric Schumacher confirmed the breach affected "all customers" but did not provide a precise number.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A consumer data breach affecting Framework via an upstream SaaS provider (Metabase) is important for customer security and data-handling practices but does not materially shift the AdTech/MarTech industry landscape.

SIGNAL RADAR

Track TechCrunch Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Framework notified all customers that hackers stole names, email addresses, phone numbers, and physical addresses.
  • Framework said customers' payment information was not included in the breach.
  • Framework attributed the breach to an upstream cyberattack at Metabase.
  • Metabase disclosed it was hacked using an unknown security flaw (zero-day) that allowed access to customers' databases.
  • Framework spokesperson Eric Schumacher confirmed the breach affected "all customers" but declined to specify a number.

Connected Companies & Entities

1 Entity mapped

“Framework’s spokesperson Eric Schumacher told TechCrunch that the breach affected “all customers,” but declined to specify a specific number...”

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: techcrunch•Published: Aug 7, 2026
Original Coverage Title: “Computer maker Framework notifies ‘all customers’ of a data breach”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Security VulnerabilityAug 8, 2026

Metabase Zero-Day (CVSS 10.0) Enables Admin Takeover

Metabase disclosed an in-the-wild zero-day: an unauthenticated SQL injection in its BI platform (rated CVSS 10.0) that allows remote attackers to write to the application database and escalate themselves to administrator. Metabase Cloud has been patched by the vendor; self-hosted deployments across six release branches must update to specific fixed versions (listed per branch) or apply the vendor-recommended temporary mitigation of blocking the /api/session/reset_password endpoint. The vulnerability exposes stored credentials for every connected database, so compromise can lead to data exfiltration across warehouses. Framework is a confirmed downstream victim; Metabase advises post-patch cleanup including revoking sessions, auditing accounts and API keys, and rotating credentials for all connected databases.

Read assessment
IdentityFeb 18, 2026

Figure Data Breach Exposes Nearly One Million Customers

Figure, a blockchain-based lending company, confirmed a data breach after hackers stole what the firm described as "a limited number of files." Security researcher Troy Hunt, creator of the breach-notification site Have I Been Pwned, analyzed the allegedly leaked dataset and found 967,200 unique email addresses tied to Figure customers. The exposed records reportedly include customer names, dates of birth, physical addresses and phone numbers. Cybercriminal group ShinyHunters claimed responsibility and published roughly 2.5 GB of data on its leak site. Figure has not publicly detailed the scope or specific types of data stolen beyond its initial statement and did not respond to inquiries about Hunt’s analysis. The incident raises privacy, fraud and regulatory risks for affected customers and data holders.

Read assessment
Market Research & Consumer Panel (data breach at market intelligence provider)Jun 22, 2026

Klue hack exposes customer data across cybersecurity firms

Market intelligence provider Klue disclosed a cyberattack that allowed hackers to exfiltrate customer data from connected cloud systems. Klue said intruders gained access on June 12 using a “compromised legacy credential” tied to an integration tool that links customers’ cloud data (such as Salesforce) to Klue. The cybercrime group Icarus claimed responsibility and threatened to publish the stolen data if a ransom is not paid. Multiple Klue customers — including Gong, Jamf, HackerOne, OneTrust, Recorded Future, Snyk, Sprout Social, Tanium, Insurity and Huntress — have confirmed data theft of business contact and some account information. Klue engaged CrowdStrike for incident response and disconnected integrations to block further access. The company has not disclosed how many customers were affected or how the credentials were obtained.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.