Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Framework

Framework Vendor Cyber Rating & Cyber Score

frame.work

At Framework, we believe the time has come for products that are designed to last. Founded in San Francisco in 2020, our mission is to remake Consumer Electronics to respect people and the planet. We've started with two award-winning products: the Framework Laptop 13 and 16. Our laptops are thin, light, high-performance notebooks that can be upgraded, customized, and repaired in ways that no other notebook can. Alongside this, we've launched the Framework Marketplace to enable an ecosystem of parts and modules. In 2025, we added two new products to our lineup: The Framework Laptop 12, a 2-in-1 convertible with a 12.2" touchscreen and stylus support, and our first non-laptop product, the highly customizable and powerful Framework Desktop,


Framework A.I CyberSecurity Scoring

Framework
Company Information
Website:https://frame.work
Employees number:169
Number of followers:39,081
NAICS:334
Industry Type:Computers and Electronics Manufacturing
Homepage:frame.work
Framework Risk Score (AI oriented)
Between 600 and 649
logo
FrameworkComputers and Electronics Manufacturing
Updated:
07/08/2026
631/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Framework Global Score (TPRM)
xxxx
logo
FrameworkComputers and Electronics Manufacturing
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Framework
FrameworkPoor
Current Score
631Caa (POOR)
01000
3 incidents
-64.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
689Before Incident
Breach
07 Aug 2026Framework
Framework: Framework Laptops Hit by Data Breach Exposing All Customers

Framework Laptop Maker Discloses Major Data Breach Affecting All Customers

626After Incident
CRITICAL-63
FRA1786127124
Framework Laptop Maker Discloses Major Data Breach Affecting All Customers Framework, the San Francisco-based modular laptop company known for its right-to-repair philosophy, has confirmed a data breach exposing the personal information of its entire customer base. The incident, disclosed this week via notifications to affected users, compromised names, email addresses, phone numbers, and physical shipping addresses effectively a full directory of every individual who has purchased one of the company’s devices. The breach strikes a particularly damaging blow to Framework, which has built its brand on transparency and user trust. While the company states that no payment or financial data was accessed since credit card details were not stored in the compromised system the exposed information remains highly valuable to cybercriminals. Such data is commonly exploited for phishing attacks, SIM swapping, and identity theft. Details about the breach remain limited. Framework has not specified when the unauthorized access occurred or how long attackers had access to customer data, leaving security experts questioning the company’s handling of the incident. The lack of clarity stands in contrast to Framework’s reputation for openness, further complicating its response. The timing of the breach adds to the fallout, as the company has positioned itself as a disruptor in the tech industry, challenging traditional manufacturers with its repairable, user-friendly designs. The incident underscores the risks even transparency-focused companies face in safeguarding customer data.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Names, email addresses, phone numbers, physical shipping addressesBrand Reputation Impact: Damaging blow to brand built on transparency and user trustIdentity Theft Risk: High risk due to exposed personal informationPayment Information Risk: None (payment data not stored in compromised system)
DATA BREACH
Type Of Data Compromised: Personal InformationSensitivity Of Data: High (names, email addresses, phone numbers, physical shipping addresses)Personally Identifiable Information: Names, email addresses, phone numbers, physical shipping addresses
AUGUST 2026
755Before Incident
Breach
03 Aug 2026Framework
Framework and Metabase: Framework customer information was accessed as part of a data breach

Framework Customer Data Exposed in Metabase Breach

689After Incident
CRITICAL-66
METFRA1786131154
Framework Customer Data Exposed in Metabase Breach Framework, the manufacturer of repairable and upgradeable laptops, has disclosed a data breach affecting all its customers. In an email sent on August 6, the company revealed that customer names, login IP addresses, physical addresses, phone numbers, and email addresses were accessed during a cyberattack on Metabase, its business database provider. Payment information was not compromised. The breach occurred after an attacker exploited an unknown zero-day vulnerability in Metabase’s systems, which the provider detected on August 3. Metabase has since patched the flaw and is conducting a forensic investigation with a third-party firm to assess the full scope of the incident. The company’s findings remain preliminary. Framework confirmed it rotated credentials following the breach and found no evidence of unauthorized admin access or compromise beyond Metabase’s systems. The company is now reviewing its data storage practices with external vendors to prevent future incidents. The breach adds to Framework’s recent challenges, including supply chain disruptions and rising component costs. Earlier this year, the company raised prices twice due to memory shortages and was forced to reduce RAM in some preorders for its Framework Laptop Pro, offering full refunds to affected customers.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Customer names, login IP addresses, physical addresses, phone numbers, email addressesSystems Affected: Metabase business databaseIdentity Theft Risk: HighPayment Information Risk: None
DATA BREACH
Customer namesLogin IP addressesPhysical addressesPhone numbersEmail addressesSensitivity Of Data: Personally Identifiable Information (PII)Personally Identifiable Information: Yes
Vulnerability
03 Aug 2026Framework
Metabase: Metabase 0-Day Vulnerability Exploited in the Wild to Gain Admin Access

Critical Zero-Day Exploit in Metabase Grants Attackers Full Admin Access

689After Incident
CRITICAL-66
MET1786299845
Critical Zero-Day Exploit in Metabase Grants Attackers Full Admin Access Metabase, a popular open-source business intelligence and data visualization platform, has confirmed active exploitation of a critical zero-day vulnerability (GHSA-vwf4-m7j8-wcjf) allowing unauthenticated attackers to gain full administrator control of affected instances. The flaw, rated with a maximum CVSS score of 10.0, impacts all versions from 0.58 through 0.63. The vulnerability is an unauthenticated SQL injection in the publicly accessible POST /api/session/reset_password endpoint. Attackers can inject arbitrary SQL commands into Metabase’s database, manipulate records, and escalate privileges to an admin account. From there, they can extract stored credentials, access connected databases, and exfiltrate sensitive data. Metabase first detected the exploit on August 3, when its own cloud platform was breached. The company patched the flaw within hours, automatically securing all Metabase Cloud customers. However, self-hosted deployments remain vulnerable until administrators apply the fix. At least two companies Framework and Tally have reported data breaches linked to this zero-day, with unauthorized access to customer information, including names, addresses, phone numbers, and emails. Security teams can detect exploitation by checking logs for a specific pattern: a POST /api/session/reset_password request returning a 400 status code, followed by a GET /api/user/current request returning 200. This sequence indicates successful session hijacking, and affected instances should be considered compromised. Metabase has released patched versions (0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, or 0.63.5) for self-hosted deployments. Organizations running older versions (pre-0.58) are unaffected. If the vulnerable endpoint was exposed, security teams should revoke active sessions, audit API keys, review admin accounts, rotate database credentials, and inspect logs for unauthorized activity. Given Metabase’s role as a central data hub, this flaw poses severe risks, potentially enabling broader breaches across connected systems. Self-hosted users are urged to patch immediately.
INCIDENT DETAILS -
TYPE
Zero-Day Exploit
IMPACT
Data Compromised: Customer information (names, addresses, phone numbers, emails), stored credentials, connected database accessSystems Affected: Metabase instances (versions 0.58 through 0.63)Operational Impact: Full administrator control gained by attackers, potential broader breaches across connected systemsBrand Reputation Impact: Severe risk due to central data hub roleIdentity Theft Risk: High (PII exposed)
DATA BREACH
Customer information (names, addresses, phone numbers, emails)Stored credentialsConnected database accessSensitivity Of Data: High (PII, credentials)Data Exfiltration: YesPersonally Identifiable Information: Yes (names, addresses, phone numbers, emails)
JULY 2026
755Before Incident
JUNE 2026
755Before Incident
MAY 2026
755Before Incident
APRIL 2026
755Before Incident
MARCH 2026
755Before Incident
FEBRUARY 2026
755Before Incident
JANUARY 2026
755Before Incident
DECEMBER 2025
755Before Incident
NOVEMBER 2025
755Before Incident
OCTOBER 2025
755Before Incident
SEPTEMBER 2025
755Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Framework ?
?
What was Framework's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Framework's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Framework's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Framework's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Framework's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Framework's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Framework's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Framework's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Framework's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Framework's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Framework's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Framework's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Framework ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Framework's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Framework Cyber Scoring History | Rankiteo