Framework stated it notified "all customers" — meaning the breach hit its entire customer base . However, Framework has not publicly disclosed the exact number of affected individuals. The company's spokesperson, Eric Schumacher, told TechCrunch that the breach affected "all customers" but declined to specify a number
. One report estimated roughly 18,000 customers based on Framework's known user community size, but this is not an official figure and may be a significant underestimate
.
Framework blamed the breach entirely on Metabase, the open-source business intelligence (BI) platform that Framework used to host its analytics data . This is a textbook supply-chain attack — Framework's own systems were not directly breached, but a trusted third-party vendor was.
The attack vector was a critical unauthenticated SQL injection zero-day vulnerability in Metabase's software . Key characteristics:
/reset_password endpoint, granting full administrator access without any credentials Metabase disclosed the incident on August 6, 2026, revealing that its Metabase Cloud SaaS platform had been compromised via this previously unknown vulnerability . Key timeline and details:
Metabase warned that, beyond customer data, the exploit could expose stored database credentials, tokens, API keys, and other sensitive configuration data from affected instances . This means the blast radius extended beyond just the customer data that Framework is disclosing — attackers could potentially pivot from Metabase into other connected systems.
Framework was not the only company affected. As the Metabase investigation unfolded, at least five companies publicly confirmed they were compromised :
This pattern shows that the Metabase zero-day was exploited as a general-purpose attack against multiple cloud tenants, not a targeted breach against Framework specifically.
Framework's official notification, as reported by multiple outlets, included guidance for customers. Based on the types of data stolen and standard breach response practices, affected customers should:
Framework's spokesperson told TechCrunch the company is "deeply sorry for this breach of information" and is "reviewing and improving" its data storage methodology .