Some Supabase customers are publicly exposing reams of people’s data to the web

Security firm UpGuard found roughly 16,000 Supabase-hosted databases that exposed at least some personal data to the public web. The research identified names, addresses, phone numbers and a smaller number of passwords and authentication tokens across projects ranging from commercial services to government-related accounts.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished 1 minute agoUpdated 1 minute ago0 views
Some Supabase customers are publicly exposing reams of people’s data to the web

Why It Matters

The findings illustrate how quickly AI-assisted and low-code "vibe-coded" development can produce applications that leak sensitive data when platform defaults or developer configurations are not properly secured. Those exposures can put large volumes of personal and operational information at risk, widening the attack surface for fraud and privacy harms.

Key Facts

  • Research firm: UpGuard
  • Platform examined: Supabase
  • Estimated exposed databases: Around 16,000
  • Types of exposed data: Names, addresses, phone numbers, some passwords and authentication tokens
  • Examples of affected projects: Private conversations on an Indian adult streaming site; thousands of license plates for a U.S. valet service; contact data for an immigration/relocation service; a consulate database belonging to an African government in France; a virtual SIM farm intercepting SMS one-time passcodes.

New analysis by cybersecurity firm UpGuard indicates that roughly 16,000 databases hosted on developer platform Supabase were publicly accessible and contained at least some personal data. The exposed information included names, addresses and phone numbers, with a smaller subset of records containing passwords and authentication tokens. UpGuard’s review found the exposed datasets came from a wide variety of projects. Examples cited by the firm range from private chat logs on an Indian adult streaming service and thousands of vehicle license-plate records for a U.S. valet company to contact lists for an immigration and relocation service. The research also identified a database tied to an African government consulate in France and a virtual SIM operation used to intercept SMS one-time passcodes, a capability commonly abused in account takeover and phishing attacks. Researchers and industry observers linked the pattern of exposures to the rapid adoption of AI-driven and low-code tooling — sometimes called "vibe-coding" — which can make it easy to build apps but also increase the likelihood that generated code or default configurations omit necessary security controls. UpGuard framed its work as an attempt to measure the scale of publicly accessible user data on Supabase, noting that misconfiguration of storage and database access has been a persistent cause of large data leaks across multiple sectors. Supabase’s chief information security officer, Bil Harmer, told TechCrunch the company treats projects as "secure by default" and views security as a shared responsibility between the platform and its users. Harmer said Supabase provides secure defaults and tooling, and that it notifies affected customers when security issues are discovered. UpGuard researcher Greg Pollock said the firm’s findings are intended to raise awareness about the prevalence of such exposures. The UpGuard report adds to previous research documenting exposed Supabase databases, including instances tied to well-known startups and apps. While many of the exposed datasets identified in this analysis were located in the United States, UpGuard emphasized that the vulnerability to misconfiguration and public exposure is a global concern.

Keep Reading