UpGuard: 16,000 Supabase Databases Found Exposing User Data — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- UpGuard found approximately 16,000 Supabase-hosted databases exposing personal data to the public web, including names, addresses, phone numbers, passwords, and authentication tokens.
- Exposed databases spanned private sex-worker conversations on an Indian adult streaming site, thousands of license plates from a U.S. valet service, immigration-relocation contacts, an African government's consulate records in France, and a virtual SIM farm used to intercept one-time passcodes for scams.
- Supabase reached a $10 billion valuation this year amid a boom in AI vibe-coded apps hosted on its platform, despite long-standing criticism over customer-side misconfigurations.
- Supabase CISO Bil Harmer said projects are "secure by default" and framed security as a shared responsibility, adding the company notifies affected customers when issues surface.
- UpGuard researcher Greg Pollock said the study was meant to raise awareness, building on earlier research that found exposed Supabase databases tied to Y Combinator startups and other popular apps.
- The AI vibe-coding boom is driving a new wave of data breaches, as generated code can contain security flaws or require configuration steps developers may not know about.
Why it matters: Roughly 16,000 databases' worth of personal records — spanning at least four countries and use cases from license-plate tracking to scam infrastructure — sat publicly accessible on a platform that just hit a $10 billion valuation, exposing a direct contradiction between Supabase's "secure by default" claim and the customer-side reality of its fastest-growing user base: AI-built apps.
Ask SkimNews




