English

SecurityUpGuardSupabase

UpGuard finds thousands of Supabase databases exposing sensitive user data

Cybersecurity firm UpGuard has found approximately 16,000 databases hosted by the development platform Supabase that are exposing sensitive personal information to the public web, according to research reported by TechCrunch.

The exposed data includes names, addresses, phone numbers, and user passwords. Some databases contained more sensitive information, such as authentication tokens and private conversation details. Examples of exposed data include information related to an African consulate in France and contact details for users of an immigration service.

The findings suggest that the rise in "vibe-coding"—the use of AI tools to rapidly build applications—may be contributing to increased data exposure. While AI helps developers build apps more easily, the generated code or the resulting application configurations can contain security flaws or improper settings that leave databases accessible to the internet.

Supabase Chief Information Security Officer Bil Harmer stated that the company provides "secure defaults and tooling," but emphasized that security is a shared responsibility between the provider and its customers. Harmer noted that the company notifies affected customers when security issues are identified.

Sources

  1. Some Supabase customers are publicly exposing reams of people’s data to the web (TechCrunch AI, 2026-09-25)
  2. UpGuard