UpGuard Finds About 16,000 Supabase Databases Exposing Personal Data
Cybersecurity firm UpGuard told TechCrunch it found about 16,000 Supabase-hosted databases exposing some personal data, including names, addresses, phone numbers and passwords. Supabase says its projects are secure by default and that customers control configuration.
UpGuard told TechCrunch that the databases it found exposed names, addresses, phone numbers and user passwords. The research surfaced a smaller number of passwords and authentication tokens. The firm said the exposed data was linked to a range of projects, including private conversations with sex workers on an Indian adult streaming site; thousands of license plates from a U.S. valet service; and contact information for users of an immigration and relocation service. One database belonged to an African government’s consulate in France, UpGuard said. Another was used to intercept text messages by a virtual SIM farm for sending one-time passcodes to verify online accounts, typically for launching scams and phishing attacks. While most of the exposed datasets appeared to be located in the United States, UpGuard said the problem is worldwide.
Supabase allows web and app developers to store and run their databases. Earlier this year, the company reached a $10 billion valuation, helped by an increase in developers hosting their vibe-coded apps on the platform. But Supabase has faced criticism over how it handles user security, and there are widely documented cases of users misconfiguring or unknowingly exposing their databases to the broader internet, in some instances involving millions of records each.
The findings add to existing concerns about how apps built with AI tools can leak sensitive data through basic misconfigurations and improper security. AI tools can make it easy to build websites and apps, but the generated code can contain security flaws, or the apps may require specific configuration that developers do not know about. Over the years, countless data breaches have been linked to improperly configured storage servers, databases and websites, leading to leaks of sensitive military emails, immigration and visa applications, classified government files, hundreds of thousands of driver’s license scans and children’s personal information. The boom in AI vibe-coding is now helping fuel a new wave of data breaches, many of which are being linked to Supabase as more people use it to store data.
Supabase’s Chief Information Security Officer Bil Harmer said in a statement to TechCrunch that the company had not seen UpGuard’s research but that its projects are “secure by default.” He described security as a shared responsibility between Supabase and its customers. “We provide secure defaults and tooling, and customers control how their own projects are configured,” Harmer said, adding that the company notifies affected customers when security issues are discovered. “Security at Supabase is never finished. We care deeply about getting it right, and we’ll keep making it easier for every developer to ship securely,” he said.
UpGuard security researcher Greg Pollock said the company’s research was important for raising awareness about the issue of data exposures. The findings build on earlier research that also found exposed databases hosted on Supabase, including those by Y Combinator startups and other popular apps. Supabase has made changes to its platform over the years, including bolstering its platform and user access to databases, according to TechCrunch.
Editor's Summary UpGuard found about 16,000 Supabase-hosted databases exposing personal data, including names, addresses, phone numbers and passwords, with cases tied to adult streaming, valet, immigration and government users. Supabase says its projects are secure by default and that customers control configuration, while UpGuard says the research raises awareness of widespread exposure risks linked to AI-built apps.