Thousands of Supabase-Hosted Databases Unknowingly Leaking Sensitive Personal Data OnlineAI
25 Sept 2026, 11:17 pm (1 min ago)· 0

Thousands of Supabase-Hosted Databases Unknowingly Leaking Sensitive Personal Data Online

New security research from UpGuard reveals that thousands of databases hosted on the development platform Supabase are exposing sensitive user information to the public web.

A recent security investigation conducted by the cybersecurity firm UpGuard has uncovered that thousands of databases hosted on the developer platform Supabase are unintentionally exposing sensitive personal information to the open web. This revelation has reignited concerns surrounding cloud database management and the security practices embedded within modern software development workflows.

Nearly Sixteen Thousand Exposed Databases

According to findings shared by UpGuard, researchers identified approximately 16,000 databases where varying degrees of personal data were left publicly accessible while hosted on Supabase, a platform heavily utilized by web and application developers to store and manage backend data. Earlier this year, Supabase achieved a $10 billion valuation fueled by a surge in developers utilizing the platform to host their applications. However, the company has simultaneously faced intense scrutiny regarding how it handles user security configurations. Widely documented cases over recent months have highlighted instances where users inadvertently misconfigured their databases, exposing millions of individual records directly to the internet.

Also read

The Security Risks of AI-Generated Code

The findings emphasize the inherent risks associated with modern development tools, particularly the rise of AI-generated applications that can inadvertently spill sensitive data due to basic configuration oversights. While artificial intelligence tools enable rapid prototyping and software creation, the resulting code frequently contains underlying security flaws, or developers may remain entirely unaware of the specific configuration parameters required to secure their infrastructure. Historically, misconfigured storage servers and databases have repeatedly led to massive data breaches across industries, leaking sensitive government files, visa applications, driver license scans, and children's personal records.

Diverse Projects and Sensitive Records Impacted

UpGuard reported that the compromised databases contained publicly reachable names, home addresses, phone numbers, and user credentials, alongside a smaller volume of authentication tokens. The exposed datasets were linked to a wide array of distinct projects, including private text exchanges on an Indian adult streaming service, license plate logs from a United States valet company, and contact details gathered by an immigration relocation agency. Other impacted databases included one belonging to an African government consulate located in France and another utilized by a virtual SIM farm designed to intercept text messages for online account verifications.

Supabase Response and Ongoing Platform Security

Although the majority of these vulnerable datasets appear concentrated within the United States, researchers emphasize that the issue represents a worldwide systemic challenge impacting startups and established apps alike. In response to ongoing security discussions, Supabase Chief Information Security Officer Bil Harmer stated that while the company had not yet reviewed the specific research, its projects are secure by default. Bil Harmer noted that security is a shared responsibility between the platform provider and the customer, stating, "Security at Supabase is never finished." The company continues to provide secure infrastructure defaults while notifying customers whenever configuration vulnerabilities are detected.

Questions & Answers

What is Supabase?
Supabase is a development platform that allows web and app developers to store and run their backend databases.
How many databases did UpGuard find exposed?
UpGuard found around 16,000 databases where personal data was exposed on the public web.
What kind of information was found in the exposed databases?
The databases contained accessible names, home addresses, phone numbers, user passwords, and various project-related records.
Who is the Chief Information Security Officer of Supabase?
The Chief Information Security Officer of Supabase is Bil Harmer.

Comments 0

No comments yet — be the first.

Citizen journalism

Become a TrendKia journalist

Voice of the people

Share news, photos and videos from your area with TrendKia and let your voice reach the nation. Every citizen a journalist.

Join now
CH 01 LIVE
TrendKia TV ON AIR
Chamar no WhatsApp