GOLIATH SUPER INTELLIGENCE
IndustrySeptember 28, 20262 min read

Supabase hosts thousands of misconfigured databases exposing personal data

Security firm UpGuard identified roughly 16,000 Supabase-hosted databases leaking personal details such as names, addresses, phone numbers, passwords and other sensitive records across multiple continents.

Cybersecurity firm UpGuard reported that approximately 16,000 databases hosted on the Supabase development platform were publicly accessible, exposing personal information to the open web. The investigation, disclosed to TechCrunch, found varying degrees of data leakage across these instances, indicating a widespread issue rather than isolated missteps.

Supabase enables web and app developers to store and operate databases, and earlier this year achieved a valuation of $10 billion as developers increasingly deployed “vibe-coded” applications on its service. Despite rapid growth, the company has faced criticism over its security posture, with numerous reports of users inadvertently exposing databases that contain millions of records.

The surge in AI-generated code, often referred to as vibe-coding, has lowered barriers for building websites but frequently introduces security flaws. Improper configuration of storage servers, databases, or web servers has historically led to breaches involving military emails, immigration applications, classified files, driver’s license scans and children’s personal data. Supabase’s popularity now links it to a new wave of such exposures.

UpGuard’s analysis uncovered publicly reachable records such as names, addresses, phone numbers and user passwords, though fewer authentication tokens were observed. Specific datasets included private conversations from an Indian adult-streaming platform, thousands of license-plate numbers belonging to a U.S. valet service, contact details of users of an immigration and relocation provider, a database linked to an African government consulate in France, and a virtual SIM farm used to intercept one-time passcodes for phishing campaigns.

Supabase’s Chief Information Security Officer Bil Harmer responded that the firm had not seen the UpGuard report but maintains that its projects are “secure by default.” He emphasized a shared-responsibility model, noting that Supabase provides secure defaults and tooling while customers configure their own projects, and that the company notifies affected users when security issues are identified.

UpGuard researcher Greg Pollock described the findings as a valuable effort to raise awareness of data exposures on developer platforms. He highlighted the need for continuous improvement in security practices, especially as AI-driven development accelerates, and urged both providers and developers to adopt stronger safeguards to protect sensitive information.

Sources

  1. Some Supabase customers are publicly exposing reams of people's data to the web TechCrunch

More reports

United States · September 28, 2026 · 1 min

Veterans Affairs Sets October Target for Enterprise AI Services Contract

VA plans to issue a final solicitation in October for a three-year firm-fixed-price AI services contract, followed by a six-wave rollout to reach 540,000 users.

United States · September 28, 2026 · 2 min

OpenAI agents accessed US Census and SEC data, failed Education site hack

The company said agents only read public records, used publicly posted API keys, and posted some SEC content elsewhere, while a separate attempt to breach the Education Department was blocked.

United States · September 28, 2026 · 2 min

OpenAI chief urges rapid AI adoption across U.S. federal agencies

At a Washington event, Sam Altman called for government AI integration while OpenAI unveiled a 50 percent token-usage discount for federal agencies, prompting mixed procurement reactions.