Looks like it happened to people that returned their framework for repair in Europe:
Dear Valued Framework Customer,
We have been informed by our repair center partner LMR Germany that due to a vulnerability in their web infrastructure, some personally identifiable information (PII) relating to your Framework return or repair may have been visible temporarily to unauthorized viewers.