logo
Sensitive Data Exposed on Supabase as Security Misconfigurations Rise
Technology iconTechnology25 Sept 2026

Sensitive Data Exposed on Supabase as Security Misconfigurations Rise

Research shows 16,000 databases on Supabase expose sensitive data, underscoring the risks of user misconfigurations in cloud platforms.

Data Breach Concerns at Supabase

A recent security assessment by cybersecurity firm UpGuard has revealed that approximately 16,000 databases hosted on the development platform Supabase are publicly exposing sensitive personal data. This alarming finding comes as Supabase, which enables web and app developers to manage their databases, has seen a surge in popularity, recently achieving a $10 billion valuation.

The Nature of the Exposed Data

UpGuard's investigation identified a concerning trend involving user misconfigurations that result in significant data exposure. The leaked information includes names, addresses, phone numbers, and even user passwords. The database breaches encompass a wide array of sensitive projects, with a few notable examples including:

  • Personal interactions from an Indian adult streaming site
  • License plate data from a U.S. valet service
  • Contact details related to an immigration and relocation service
  • Sensitive communications tied to a consulate office in France

These revelations underscore the critical vulnerabilities associated with poorly configured databases. In particular, the findings highlight a troubling link between the rise of AI-generated coding tools and an increase in security breaches, as many users may be unaware of the necessary security configurations.

Misconfigurations and the Role of Developers

Historically, numerous data breaches have stemmed from poorly configured storage systems and web services. From classified government documents to personal records, these vulnerabilities have allowed sensitive information to be accessed by unauthorized parties. UpGuard pointed out that the pitfalls of vibe-coded applications often lead developers to inadvertently expose data, emphasizing a growing need for comprehensive awareness and education within the developer community.

Greg Pollock, a security researcher with UpGuard, emphasized the significance of their report, noting that it sheds light on the broader implications of these security missteps. "Awareness is crucial," he stated. "Our research aims to underscore the potential risks associated with misconfigured databases."

Supabase’s Response to Security Concerns

In light of the report, Supabase’s Chief Information Security Officer, Bil Harmer, reaffirmed the company's commitment to secure practices. He noted that while Supabase provides "secure by default" tools, the responsibility for security ultimately lies with users.

"Our projects are designed to be secure, but customers control how their projects are configured. We actively inform clients of any security issues we uncover," Harmer explained. Supabase continues to enhance its platform with robust access controls to help mitigate these issues further.

Despite the currently visible data exposure problems, Supabase maintains that the security of its system is an ongoing process. Harmer encouraged developers to remain vigilant about their database configurations and highlighted the importance of continuous improvement in security practices.

Looking Forward

As the reliance on platforms like Supabase increases, the critical lesson from these data breaches serves as a wake-up call for developers across the industry. Implementing proper security measures and being mindful of configuration details are essential steps in safeguarding sensitive data against potential breaches. As UpGuard and Supabase work to raise awareness and implement improvements, it remains imperative that users take an active role in protecting their information.

Popular news

Netanyahu dismisses West Bank violence as actions of 'juvenile delinquents' during a UN speech, focusing on Israel's military success against Hezbollah.

Subscribe to
our news

Get the most important updates and top stories in your inbox.

mail