Framework Computer, the Bay Area startup that built its entire brand on repairable, modular laptops, has spent the last few years earning a reputation as the anti-Apple: a company that treats customers like adults who deserve schematics, spare parts, and straight talk. That reputation is now being tested in a different way. Framework has begun emailing what it describes as its entire customer base to disclose a data breach, and the notice covers everyone who has ever bought a Framework Laptop 13, a Framework Laptop 16, a mainboard, or even a single Expansion Card.
The disclosure is notable not because of the scale of stolen payment data — Framework says card numbers were never exposed — but because of what it reveals about how even security-conscious hardware companies remain vulnerable through the vendors and support systems wrapped around their core business.
What Actually Happened
According to the breach notification letter and a corresponding filing with the Office of the Maine Attorney General — a common disclosure route because Maine requires notice for breaches affecting even a single resident — Framework detected unauthorized access tied to a system that supports its e-commerce and customer account infrastructure. The company has not named the specific third-party vendor publicly, a common practice when litigation or vendor contracts restrict disclosure, but it has confirmed the intrusion originated outside Framework’s own core codebase rather than through its laptops’ firmware or the Framework BIOS supply chain.
That distinction matters. Framework has spent years building trust around the security of the hardware itself — coreboot support, open-source EC firmware, and a DIY Edition that lets buyers inspect exactly what’s running on their machine. This incident sits entirely on the business-operations side: accounts, orders, and support tickets, not the silicon.
Framework’s notice states the exposure did not include full payment card numbers, since transactions are tokenized through its payment processor and never stored on Framework’s own servers in raw form.
Timeline of Disclosure
- Detection: Framework says it identified anomalous access patterns during a routine security review of backend systems.
- Investigation: A third-party forensics firm was brought in to scope the intrusion and determine what data sets were touched.
- Containment: Access to the affected system was cut off and credentials rotated once the entry point was confirmed.
- Notification: Emails went out to the full customer database, including people who registered a warranty, created a Framework Marketplace account, or simply placed a single order years ago.
What Data Was Exposed
Framework’s letter is careful to draw a line between what was and wasn’t accessed. That specificity is useful, because it tells you exactly what kind of follow-on attacks to expect — mostly phishing and social engineering rather than direct financial fraud.
| Data Type | Exposed? | Practical Risk |
|---|---|---|
| Full name and email address | Yes | Enables targeted phishing referencing real order history |
| Shipping address | Yes | Low direct risk, but useful for spear-phishing believability |
| Order history / product SKUs | Yes | Attackers can fake “your Framework 16 mainboard shipment” emails |
| Account password (hashed) | Partial | Reused passwords elsewhere become vulnerable via credential stuffing |
| Full payment card number | No | Tokenized by payment processor, not stored by Framework |
| Social Security number / government ID | No | Not collected by Framework at checkout |
The presence of order history in the exposed data set is the detail worth paying attention to. A generic phishing email is easy to ignore. An email that correctly references your Framework Laptop 13 DIY Edition order from March 2023 and asks you to “verify your warranty” is a different threat entirely.
Why This Stings More for Framework Than for a Typical Retailer
Framework isn’t Best Buy or Dell. It’s a company of a few hundred employees that built its entire customer relationship on trust, transparency, and a direct-to-consumer model with no big-box retail buffer in between. Nearly every customer has interacted directly with Framework’s website, its Cortex community forum, or its support ticketing system — which means the notification genuinely does reach almost everyone who has ever bought from the company since its 2021 launch.
- No retail intermediary: Unlike laptop buyers who purchase through Best Buy or Amazon, most Framework customers created accounts directly with Framework, meaning more personal data lived in Framework’s own systems.
- Enthusiast, security-literate audience: Framework’s buyer base skews toward Linux users, right-to-repair advocates, and IT professionals — people who will scrutinize a breach notice far more closely than the average consumer.
- Brand built on transparency: Framework routinely publishes teardown guides and open specifications; a breach notice that feels vague or slow would cut against everything the brand claims to stand for.
- Small company, limited security headcount: Framework has never disclosed a dedicated internal security team of significant size, meaning much of its infrastructure — like many startups its size — likely leans on third-party SaaS vendors for support, marketing, and order management.
How Framework Has Responded
The company’s public posture has focused on speed of disclosure and specificity rather than minimizing the incident. That’s a meaningfully different approach than the vague “we take security seriously” template many larger corporations use.
- Notified all customers rather than narrowing the disclosure to a smaller “affected” subset, opting for over-inclusion.
- Forced password resets for Framework Marketplace and Framework account holders tied to the affected system.
- Engaged an external forensics firm to independently verify the scope of the intrusion.
- Filed formal notice with state regulators, including Maine, triggering the paper trail that made this breach publicly documented.
- Published guidance directly to customers about phishing risk tied to the specific data categories exposed.
Putting It in Context: This Is Part of a Bigger Pattern
Framework’s breach is small in absolute numbers compared to the mega-breaches that have defined the last two years, but it fits a pattern security researchers have been flagging since 2023: attackers increasingly go after the software vendors sitting behind a company’s storefront rather than the company itself.
- The MOVEit Transfer breach in 2023, exploited by the Clop ransomware group, ultimately hit more than 2,600 organizations worldwide — not because those companies were individually careless, but because they all used the same vulnerable file-transfer software.
- The Snowflake data-warehouse incidents in 2024 exposed customer records at AT&T (73 million customers), Ticketmaster (560 million), and dozens of other companies that all relied on the same cloud data platform with weak default authentication.
- Email and marketing platforms like Klaviyo have previously been compromised, exposing customer mailing lists for dozens of e-commerce brands simultaneously, including several crypto companies in 2022.
The common thread: a breach notice from a small, well-regarded brand doesn’t necessarily mean that brand got sloppy. It often means an upstream vendor did, and the downstream company is left holding the notification obligation — and the reputational fallout.
What Framework Customers Should Actually Do Right Now
Security advice after a breach is often generic to the point of being useless. Here’s what actually matters given the specific data categories Framework has confirmed were exposed.
- Reset your Framework account password immediately, even if you were forced to during the notification process — and make it unique to that account.
- Check for password reuse. If your Framework password was used anywhere else (email, banking, other retailers), change it there too. Use a password manager like Bitwarden or 1Password to generate unique credentials going forward.
- Enable two-factor authentication on your Framework account and, more importantly, on your primary email account — since email is the master key attackers use to reset everything else.
- Be suspicious of “order verification” emails referencing specific Framework products, order numbers, or shipping addresses over the next several months. Verify directly through Framework’s official site rather than clicking email links.
- Watch for SMS and phone-based phishing (“smishing”), since exposed shipping data can support fake delivery-related scams referencing real orders.
- Monitor for unusual account activity on Framework Marketplace, including unauthorized order placement using saved shipping info.
What This Means for Framework’s Business Going Forward
Framework has built its entire market position around a promise: buy from us because we respect you enough to let you fix, upgrade, and understand your own machine. A data breach doesn’t undo the mainboard upgrade path or the modular Expansion Card ecosystem, but it does introduce a new kind of question for a company that has marketed itself as different from the incumbents it’s trying to displace.
Dell, HP, and Lenovo have all suffered data breaches over the years without meaningfully denting their sales, largely because their customers weren’t buying based on a trust-and-transparency narrative in the first place. Framework’s customer base is smaller, more vocal, and more likely to hold the company to the standard it set for itself.
Key Risks and Mitigating Factors
- Risk: Enthusiast community members are more likely to publicly scrutinize the technical adequacy of Framework’s response on forums like Reddit’s r/framework and Hacker News.
- Mitigating factor: Framework’s decision to notify its entire customer list rather than a narrow subset, combined with no exposed payment data, limits direct financial harm.
- Risk: Repeat incidents, even minor ones, would compound distrust faster for a values-driven brand than for a commodity PC maker.
- Mitigating factor: Framework’s core differentiator — repairable hardware — is unrelated to the software vendor issue, so the product proposition itself remains intact.
The Bottom Line
Framework’s breach notification is a reminder that a company can do almost everything right on the hardware side — open specs, replaceable parts, a right-to-repair posture that regulators in California and the EU are actively pushing the rest of the industry toward — and still get bitten by the unglamorous back-office systems that every online retailer depends on. The exposure here is real but bounded: no card numbers, no government IDs, mostly contact and order data that fuels phishing rather than direct financial theft.
What will actually determine whether this dents Framework’s reputation isn’t the breach itself. It’s whether the company’s notoriously engaged customer base — the same people who write 5,000-word teardown posts about hinge mechanisms — decides Framework handled the disclosure with the same transparency it demands of its hardware. Early signs, including the decision to notify everyone rather than a narrower group and to spell out exactly what wasn’t taken, suggest the company is trying to extend its repairability ethos into how it handles a mistake, not just how it builds a laptop.
Frequently Asked Questions
Did Framework’s breach expose my credit card number?
No. Framework’s notification states that payment card numbers are tokenized through its payment processor and were never stored in raw form on the systems that were accessed, so card data was not part of the exposure.
Why did Framework notify customers who haven’t ordered anything in years?
Framework opted for a broad, inclusive notification rather than narrowing the disclosure to a specific date range, likely because account and order records going back to the company’s 2021 launch were stored in the same affected system. Regulators generally favor over-notification when the exact scope of exposure is hard to pin down precisely.
Should I stop buying from Framework because of this breach?
Not necessarily. The breach involved back-office systems rather than the security of Framework’s laptops, firmware, or BIOS, and the company’s response — full disclosure, forensic investigation, forced password resets — matches or exceeds how most PC makers have historically handled similar incidents. The bigger practical step for any customer is reusing unique passwords and enabling two-factor authentication, regardless of which retailer they shop with.
