Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
CLAY TRIBUNE.
Advertisement

Supabase Customers Expose 16,000 Databases of Personal Data to the Web

16,000 Supabase databases exposed data online; passwords, emails, license plates and classified files found in security research.

By mitch·5 min read
Illustration of scattered broken databases leaking personal data across a web server rack.

New security research from cybersecurity company UpGuard says thousands of databases hosted on development platform Supabase are leaving people’s sensitive information exposed to the public web.

TechCrunch spoke with UpGuard, which reported identifying roughly 16,000 databases exposed by Supabase while they were being hosted on the platform. Supabase serves as a hosting service for web and app developers, letting them store and run their databases.

Supabase’s rise and its security track record

This year, Supabase hit a $10 billion valuation because more developers are hosting their vibe-coded apps on the platform. The company has also come under fire over how it handles user security. Plenty of well-documented reports describe users misconfiguring or exposing their databases to the broader internet, in some cases involving millions of records each.

Advertisement

The results show that apps and sites using the vibe-code style can let out sensitive information because the settings are not set up correctly or because there is not enough security put in. Building websites and apps with AI tools is simple, but the code that comes out can sometimes carry security problems, or the apps may need certain settings that the person building them does not know about.

Throughout history, numerous data breaches have been tied to storage servers, databases and websites that were not set up properly. These incidents have led to the leaks of sensitive military emails, immigration and visa applications, classified government files, and hundreds of thousands of driver’s license scans and children’s personal information.

A new surge in data breaches is being fueled by the boom in AI vibe-coding, with many of these breaches now being tied to Supabase as more people store their data there.

What UpGuard found

UpGuard’s research aimed to gauge the scale of exposed data across the platform, and it found publicly accessible names, addresses, phone numbers, and user passwords. A smaller number of passwords and authentication tokens were among the findings.

The firm said the databases held data tied to several projects, including private conversations with sex workers on an Indian adult streaming site, the contact details of people who used an immigration and relocation service, and thousands of license plates of a U.S. valet service. UpGuard said one of the databases belonged to an African government’s consulate in France, and another was used by a virtual SIM farm for intercepting text messages to send one-time passcodes and verify online accounts, typically for launching scams and phishing attacks.

Where the exposed databases live

UpGuard has indicated that this issue is a global one, even though the bulk of the revealed datasets appear to be found in the United States. The new findings continue the earlier research, which found a variety of exposed databases hosted on Supabase, including those belonging to Y Combinator startups and other popular apps.

Supabase’s response

When reached for comment, Supabase’s Chief Information Security Officer Bil Harmer said that while the company has not seen the research, its projects are “secure by default.” He described security as a shared responsibility between the company and its customers. “We provide secure defaults and tooling, and customers control how their own projects are configured,” he said. “The company notifies affected customers when security issues are discovered.”

The company has not seen the research, but Harmer said its projects are “secure by default.” He described security as a shared responsibility between the company and its customers. “We provide secure defaults and tooling, and customers control how their own projects are configured,” and the company notifies affected customers when security issues are discovered, he said.

“Security at Supabase is never finished. We care deeply about getting it right, and we’ll keep making it easier for every developer to ship securely,” Harmer added.

The stakes of misconfigured databases

Greg Pollock, an UpGuard security researcher, said the company’s research was important for raising awareness about the issue of data exposures.

Security research shows a familiar dynamic: developers can build apps faster than ever, but the tools they use can carry risk the developer never thinks to check. Supabase offers the platform and the defaults, but the choices about access, encryption and exposure sit with the customer. Harmer described that shared responsibility when he said security is a joint effort.

What developers should check

The findings from UpGuard make clear that relying on defaults alone is not sufficient when you are building on Supabase or any other platform. What is required instead is a working knowledge of how a secure-by-default system operates, so that you can sustain that security rather than trust it by chance.

The records are laid bare for all to see. They are exposed to all who look. What follows is uncertain, and it will be decided by the people who build these systems. The lesson is clear: the default settings are not enough, and the person building the app is always the weakest link.

Purpose Exposure Type Example
Private conversation archive Private communications Sex worker conversations on an Indian adult streaming site
Vehicle data License plates Thousands of plates for a U.S. valet service
Contact information Names, addresses, phone numbers Immigration and relocation service users
Authentication data Passwords, tokens Intercepted text messages from a virtual SIM farm
Government data Classified files An African government’s consulate in France

Source material: “Some Supabase customers are publicly exposing reams of people’s data to the web,” TechCrunch.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.