Like yes, it's technically not Framework's fault
I know it's a third party vendor that got hacked, but I really think the blame still falls on the company that contracted with the vendor.
Framework decided to hire this company and companies need to recognize the risk in hiring SaaS companies. I know at my previous job we had to go through security and privacy compliance reviews to decide it was even worth sharing data with a third party vendor.
Too many companies have a ton of SaaS providers and shovel customer data to each one.