Cybersecurity

Security Research: Nearly 16,000 Supabase Databases Exposed Personal Data to the Public

UpGuard found that nearly 16,000 databases hosted on Supabase made some personal data accessible online, including names, addresses, phone numbers, passwords, and authentication tokens. The findings highlight the risks of applications built with artificial intelligence tools when access settings and databases are left inadequately secured.

2026-09-25
3 min read
107 views
certi.news Editorial Team
Security Research: Nearly 16,000 Supabase Databases Exposed Personal Data to the Public

Security research conducted by UpGuard found that nearly 16,000 databases hosted on the Supabase platform allowed the public to access some personal data. The data discovered by the company included names, addresses, phone numbers, and passwords, as well as a smaller number of authentication tokens.

Supabase is used to store and run application databases, and demand for it has increased with the spread of applications that developers build quickly using artificial intelligence tools and what is known as vibe coding. According to the research, the problem was not with the platform alone, but with databases or projects configured in a way that made the data accessible over the public internet.

Varied Data and Highly Sensitive Cases

UpGuard said the exposed databases included private conversations with sex workers on an adult livestreaming website in India, thousands of license plates belonging to a valet parking service in the United States, and contact information for users of an immigration and relocation service. One case also involved a database linked to an African government consulate in France, while another was used to intercept text messages from a virtual SIM farm that sends one-time verification codes, a mechanism that could be exploited in fraud and phishing operations.

According to the company, the majority of the datasets it identified were concentrated in the United States, but it emphasized that the problem is global. The research follows previous investigations that found exposed databases hosted on Supabase, including databases linked to Y Combinator startups and well-known applications.

Why Does This News Matter?

The issue reveals a practical aspect of the risks of developing applications with artificial intelligence: an application's ability to be generated as a working product does not mean that its database settings or access policies are secure. The resulting code may contain vulnerabilities or require security configurations that the developer does not recognize, making a simple mistake a cause of millions of records being exposed.

Numerous precedents confirm that improperly configured storage servers, databases, and websites have been linked to leaks involving military messages, immigration and visa applications, confidential government files, copies of driver's licenses, and children's data. Therefore, the impact of the problem is not limited to application developers; it also extends to users and organizations that rely on these services to store sensitive information.

Shared Responsibility and Open Questions

Bil Harmer, Supabase's chief information security officer, said the company had not reviewed the research, but described the platform's projects as “secure by default.” He added that security is a shared responsibility: Supabase provides default settings and protection tools, while customers control how their projects are configured, with affected customers being notified when security issues are discovered.

This response clarifies the limits of what the platform's default settings can guarantee: access permissions, security rules, and reviewing exposed data remain operational responsibilities of customers. The text does not specify the number of organizations or records that were actually accessed, nor does it establish that all the databases mentioned were breached or copied; the announced finding concerns the possibility of public access to the data.

News source
TechCrunch AI
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news