Skip to content
Breaking:

UpGuard Finds Roughly 16,000 Supabase Databases Exposing Personal Data

Security researchers attribute widespread misconfigurations to developer oversight and the growing reliance on AI-generated code.

By The Company Wire3 min read
Share
Supabase — UpGuard Finds Roughly 16,000 Supabase Databases Exposing Personal Data
Supabase — UpGuard Finds Roughly 16,000 Supabase Databases Exposing Personal Data. Photo: TechCrunch AI.

Thousands of databases hosted by development platform Supabase are exposing sensitive personal data on the open web due to customer misconfigurations, according to findings from cybersecurity firm UpGuard reported by TechCrunch AI (https://techcrunch.com/2026/09/25/some-supabase-customers-are-publicly-exposing-reams-of-peoples-data-to-the-web/).

UpGuard told TechCrunch that it discovered approximately 16,000 databases hosted on Supabase where some degree of personal data was publicly accessible. Researchers tied the wave of exposures in part to the rise of AI-assisted development, or vibe-coding, where automated code generation can introduce security flaws or require configurations that developers fail to implement properly.

Supabase, which reached a $10 billion valuation earlier this year as adoption surged among developers building applications, provides backend database hosting. However, the platform has faced criticism as misconfigured customer instances have repeatedly exposed records across the internet.

The exposed information identified by UpGuard included names, physical addresses, and phone numbers, alongside a smaller volume of passwords and authentication tokens. While most exposed datasets were tied to U.S. entities, UpGuard emphasized that the problem is global.

Specific exposed datasets included private conversations from an Indian adult streaming site, thousands of license plate records from a U.S. valet service, and contact details from an immigration and relocation service. UpGuard also identified an exposed database belonging to an African government's consulate in France and another run by a virtual SIM farm used to intercept SMS verification codes.

These findings build on prior research detailing exposed Supabase databases operated by Y Combinator-backed startups and other applications. Greg Pollock, a security researcher at UpGuard, noted that the investigation aimed to increase industry awareness around cloud data exposure risks.

In response, Supabase Chief Information Security Officer Bil Harmer stated that while the company had not reviewed the specific research, its projects are secure by default. Harmer emphasized a shared responsibility model, noting that Supabase provides secure baseline configurations and tools while customers control their project settings, adding that Supabase alerts customers when security issues are discovered.

Sources

  1. TechCrunch AI

Company: Supabase

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.