Key facts
- Thousands of databases hosted on Supabase have exposed sensitive personal information to the public web.
Thousands of databases hosted on the development platform Supabase have exposed sensitive personal information to the public web, according to cybersecurity firm UpGuard. The exposures stem from customer misconfigurations of the platform's security settings, highlighting risks associated with AI-generated code and improper app development.

The widespread exposure of sensitive personal data due to misconfigurations on platforms like Supabase highlights the significant security risks associated with modern app development, particularly with the increasing use of AI tools. This poses a direct threat to individuals whose data is compromised and to businesses that rely on these platforms for data storage and management.
Thousands of databases hosted on the development platform Supabase are publicly exposing sensitive personal information, according to new research by cybersecurity firm UpGuard. The firm identified approximately 16,000 databases where personal data was accessible on the public web. These exposures are largely attributed to customer misconfigurations of the platform's security settings, a growing concern amplified by the rise of AI tools that can generate code with potential security flaws or require specific, often misunderstood, configurations.
UpGuard's research surfaced publicly accessible names, addresses, phone numbers, user passwords, and a smaller number of authentication tokens. The exposed data was linked to various projects, including private conversations from an Indian adult streaming site, license plates from a U.S. valet service, and contact information for an immigration and relocation service. Data from an African government's consulate in France and a virtual SIM farm used for sending one-time passcodes for verification, often for scams and phishing, were also found.
While the majority of the exposed datasets were located in the United States, UpGuard noted that this is a global issue. The findings build on previous research that identified exposed databases hosted on Supabase, including those from Y Combinator startups. Supabase has previously made changes to bolster its platform and user access controls.
In response, Supabase's Chief Information Security Officer Bil Harmer stated that the company provides secure defaults and tooling, emphasizing that customers control their project configurations. He added that Supabase notifies affected customers when security issues are discovered and that security is an ongoing effort.
Pick the topics you care about. Get only what matters, on your cadence.