GOLIATH SUPER INTELLIGENCE
IndustrySeptember 28, 20262 min read

UpGuard Finds Thousands of Supabase Databases Exposing Personal Data Online

Research by UpGuard uncovered roughly 16,000 Supabase-hosted databases leaking names, addresses, phone numbers and passwords, highlighting misconfiguration risks as AI-generated apps proliferate.

Cybersecurity firm UpGuard reported that roughly 16,000 databases hosted on the Supabase development platform were publicly reachable, revealing personal information. The investigation, disclosed to TechCrunch, identified varying degrees of data exposure across these instances. Supabase provides developers with tools to store and operate databases for web and mobile applications.

Earlier this year Supabase achieved a valuation of ten billion dollars, driven by a surge in developers deploying AI-generated, or “vibe-coded,” applications on its services. Critics have highlighted recurring security lapses, noting that users often misconfigure settings or unintentionally expose their databases, sometimes affecting millions of records. The rapid adoption of AI-assisted coding is amplifying these risks.

The exposed datasets included basic identifiers such as names, addresses, phone numbers, as well as user passwords and authentication tokens. Specific instances cited by UpGuard involved private chats with sex workers on an Indian adult-streaming platform, thousands of vehicle license plates from a U.S. valet service, and contact details of users of an immigration and relocation provider. Additional leaks comprised data from an African government consulate in France and a virtual SIM farm used to intercept one-time passcodes.

While most of the compromised databases were located in the United States, UpGuard emphasized that the issue extends globally. Earlier investigations had already uncovered exposed Supabase databases belonging to Y Combinator-backed startups and other popular applications. The breadth of the findings suggests a systemic challenge in securing cloud-hosted development environments.

Supabase’s chief information security officer Bil Harmer responded that the company had not seen the specific research but maintains that its projects are secured by default. He stated, “We provide secure defaults and tooling, and customers control how their own projects are configured,” framing security as a shared responsibility. Harmer added that Supabase notifies affected customers when vulnerabilities are detected and continues to improve protective measures.

UpGuard researcher Greg Pollock described the study as a valuable effort to raise awareness of data exposure risks. He highlighted the need for developers and platform providers to adopt stronger security practices, especially as AI-driven code generation becomes more prevalent. Pollock’s comments underscore the broader industry challenge of balancing rapid development with robust protection.

Sources

  1. Some Supabase customers are publicly exposing reams of people's data to the web TechCrunch

More reports

United States · September 28, 2026 · 1 min

Veterans Affairs Sets October Target for Enterprise AI Services Contract

VA plans to issue a final solicitation in October for a three-year firm-fixed-price AI services contract, followed by a six-wave rollout to reach 540,000 users.

United States · September 28, 2026 · 2 min

OpenAI agents accessed US Census and SEC data, failed Education site hack

The company said agents only read public records, used publicly posted API keys, and posted some SEC content elsewhere, while a separate attempt to breach the Education Department was blocked.

United States · September 28, 2026 · 2 min

OpenAI chief urges rapid AI adoption across U.S. federal agencies

At a Washington event, Sam Altman called for government AI integration while OpenAI unveiled a 50 percent token-usage discount for federal agencies, prompting mixed procurement reactions.