IT-PUB NEWS

UpGuard finds exposed data in thousands of Supabase databases

28.09.2026 12:03 • Author: IT-PUB
UpGuard finds exposed data in thousands of Supabase databases

UpGuard says about 16,000 Supabase databases exposed personal data, underscoring how AI-built apps can repeat old security mistakes at scale.

Thousands of databases hosted on Supabase have been found exposing sensitive information to the public web, according to new research from cybersecurity firm UpGuard. The findings put a spotlight on a growing problem in the AI app-building boom: developers can launch websites and apps quickly, but basic security mistakes can still leave personal data open to anyone who knows where to look. UpGuard says it identified around 16,000 databases with some level of personal data exposed while hosted on Supabase. That makes this more than a one-off leak.

Supabase is widely used by web and app developers to store and run databases, and the research suggests a broader pattern of exposure across projects built on the platform, including those created with so-called vibe-coding tools. As IT-PUB News notes, the concern here is not a single breach, but repeated misconfigurations across many separate projects.

Exposed databases contained names, passwords and tokens

According to UpGuard, the publicly accessible data included names, addresses, phone numbers and user passwords. In a smaller number of cases, the firm also found passwords and authentication tokens.

The company said the exposed databases were tied to a range of projects. These included private conversations with sex workers on an Indian adult streaming site, thousands of license plates from a U.S. valet service, and contact details of people who used an immigration and relocation service.

UpGuard also said one database belonged to an African government’s consulate in France. Another was used to intercept text messages through a virtual SIM farm that sent one-time passcodes to verify online accounts, which are often used in scams and phishing attacks.

That helps explain why database misconfigurations draw attention well beyond the tech world. When sensitive records are left exposed, the fallout can hit ordinary users, businesses and public institutions alike.

AI app building is making old security mistakes easier to repeat

UpGuard links the problem to the rise of vibe-coded apps and websites. These projects are built quickly with AI tools, making app creation easier for people without deep development experience. The trade-off is familiar: generated code can include security flaws, and some apps may require settings their builders do not fully understand.

This is an old problem, but one that may now be easier to reproduce at scale. Many past breaches have come from storage servers, databases and websites that were set up incorrectly rather than compromised through sophisticated attacks. The source text points to earlier leaks involving military emails, immigration and visa applications, classified government files, driver’s license scans and children’s personal information.

What has changed, UpGuard argues, is the volume. As more people use AI tools to build apps and store data, more projects may end up exposed through simple configuration errors. The threat is not a new kind of cyberattack so much as a faster way to repeat an old one.

Supabase says security is shared with customers

Supabase has become a major name in this market. Earlier this year, the company reached a $10 billion valuation, helped by the rise of developers hosting vibe-coded apps on the platform. At the same time, it has faced criticism over how user security is handled, with documented cases of customers misconfiguring databases or exposing them to the wider internet, sometimes involving millions of records.

The company has made changes over time, including strengthening its platform and improving user access to databases. Asked to comment, Supabase Chief Information Security Officer Bil Harmer said the company had not seen the research but described its projects as “secure by default.”

Harmer said security is a shared responsibility between Supabase and its customers. “We provide secure defaults and tooling, and customers control how their own projects are configured,” he said, adding that the company notifies affected customers when security issues are discovered.

He also said: “Security at Supabase is never finished. We care deeply about getting it right, and we’ll keep making it easier for every developer to ship securely.”

The tension is clear. Platforms can offer safer defaults, but they cannot fully prevent developers from making mistakes in how they configure their own projects.

UpGuard says the exposure is not limited to one market

UpGuard said the issue is worldwide, even though most of the exposed datasets it found appeared to be located in the United States. The firm also said its latest findings build on earlier research that uncovered exposed databases hosted on Supabase, including those connected to Y Combinator startups and other popular apps.

For users, the practical concern is simple: personal data may be exposed without any obvious sign that something is wrong. For businesses and public organizations, the risks include reputational damage, legal exposure and the loss of trust that can follow a data leak.

For the broader digital ecosystem, the research is another reminder that AI-assisted development does not eliminate security work. It can speed up building, but it can also make it easier to ship software before settings, permissions and storage controls are fully understood. UpGuard researcher Greg Pollock said the company’s work was meant to raise awareness about data exposure, which remains a basic but persistent problem in modern app development.


Improve SEO for a small/medium business website for $50