
Researchers found 16,000 Supabase databases publicly exposing personal data
Researchers at the cybersecurity firm UpGuard found roughly 16,000 databases hosted on Supabase that were publicly exposing personal data. Supabase says its projects are secure by default and that security is a shared responsibility.
Security researchers at the cybersecurity firm UpGuard have found roughly 16,000 databases hosted on Supabase that were publicly exposing personal data to the open web. UpGuard shared the findings with TechCrunch.
Supabase is a development platform where teams store and run the databases behind web and mobile apps. The company reached a $10 billion valuation earlier this year as more developers began hosting AI-generated applications on it, but its handling of user security has drawn criticism.
What was exposed
The exposed records included names, street addresses and phone numbers, plus a smaller number of user passwords and authentication tokens. UpGuard described the problem as systemic: the data was reachable because of how individual customer projects had been configured, not because of a flaw in Supabase's own systems.
The datasets UpGuard reviewed included private conversations with sex workers on an Indian adult streaming site, thousands of license plates from a U.S. valet service, and the contact details of people who used an immigration and relocation service. One database belonged to an African government's consulate in France. Another was used by a virtual SIM farm to intercept text messages carrying one-time passcodes for online accounts, infrastructure typically used for scams and phishing.
Most of the exposed datasets appear to be located in the United States, UpGuard said, but the problem is worldwide.
Supabase's response
Supabase's chief information security officer, Bil Harmer, said the company had not seen the research and that its projects are "secure by default". Security, he said, is a shared responsibility between the company and its customers: "We provide secure defaults and tooling, and customers control how their own projects are configured." Harmer added that Supabase notifies customers when it discovers security issues. "Security at Supabase is never finished. We care deeply about getting it right, and we'll keep making it easier for every developer to ship securely."
Why it matters
UpGuard researcher Greg Pollock said the work was important for raising awareness about data exposure. The findings follow earlier scans that found exposed Supabase databases belonging to Y Combinator startups and other popular apps.
Misconfigured databases and storage servers have driven data breaches for years, leaking material from government files to driver's license scans. The rise of AI-assisted "vibe coding" is adding to the volume: generated code can carry security flaws, and apps may need configuration that their authors do not know about.
Supabase has updated its platform over the years, including tightening how users reach their databases.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.