Framework, the company known for modular, repairable and upgradeable computers, has notified all of its customers that hackers accessed their personal contact information in a data breach.

The notification, first reported by TechCrunch on August 7, says the attackers stole customers' names, email addresses, phone numbers and physical addresses. Crucially, payment information was not included in the stolen data.

Framework spokesperson Eric Schumacher confirmed the breach affected 'all customers', though the company declined to specify an exact number. Framework devices are a niche product, but some estimates suggest the company has sold hundreds of thousands of units.

According to the notification, the incident stems from an upstream cyberattack at Metabase, a business-intelligence vendor. Metabase disclosed its own breach on its website, saying hackers used an unknown security flaw — a so-called zero-day — to access customers' databases stored on Metabase's cloud servers. Framework's email included the message Metabase sent to the company, which said the attackers had accessed Framework's cloud instance.

Framework said it investigated the incident and confirmed the personal data was stolen, but that no payment details were taken. Metabase did not respond to a request for comment.

The breach is the latest in a string of supply-chain security incidents in which a compromise of a smaller vendor cascades into customer-facing companies. For a company whose entire brand is built on customer trust in long-lived, repairable hardware, the incident is a reminder that even the most careful hardware maker depends on the security of the software vendors it relies on behind the scenes.