Thousands of databases hosted by development platform Supabase expose people’s sensitive information to the public web, a new security study by cybersecurity firm UpGuard has found.
UpGuard told TechCrunch that it discovered about 16,000 databases that had some level of personal data leaked while hosted by Supabase, which allows web and app developers to store and run databases.
Supabase reached a $10 billion valuation earlier this year thanks to an increase in developers hosting vibe-coded apps on the platform. However, the company has faced criticism for how it handles user security. There are widely documented cases of users misconfiguring or unknowingly exposing their databases to the wider Internet, sometimes amounting to millions of records each.
The findings highlight how vibe-coded apps and websites can leak or expose sensitive data through basic misconfigurations or inadequate security. While AI tools make it easy to build websites and apps, the generated code often contains security flaws, and apps may require specific configurations that developers don’t know about.
Over the years, countless data breaches have occurred involving improperly configured storage servers, databases, and websites. Such incidents resulted in the leaking of confidential military emails, immigration and visa applications, confidential government files, hundreds of thousands of driver’s license scans, and children’s personal information.
Currently, the boom in AI vibecoding is fueling a new wave of data breaches, many of which are linked to Supabase as more and more people use it to store their data.
UpGuard said that while trying to understand the extent of the data leaked across its platforms, it found publicly accessible names, addresses, phone numbers and user passwords. This research revealed a low number of passwords and authentication tokens.
The company said the database contains data related to various projects, including private conversations with sex workers on adult streaming sites in India. Thousands of license plates for valet services in the United States. Contact information for people who have used immigration and resettlement services. One of the databases belonged to an African government consulate in France, and the other was used to intercept text messages by a virtual SIM farm for sending one-time passcodes to authenticate online accounts, and was typically used to launch fraud and phishing attacks, Upgard said.
Although the majority of these published datasets appear to be in the United States, Upgard said this is a global problem. The findings build on previous research that also found a variety of public databases hosted on Supabase, including those by Y Combinator startups and other popular apps.
Supabase has made changes to its platform over the years, including enhancing user access to the platform and database.
When asked for comment, Bill Harmer, Supabase’s chief information security officer, said that while the company had not confirmed the study, its projects were “secure by default.” He explained that security is a shared responsibility between the company and its customers. “We provide secure defaults and tools that give customers control over how their projects are configured,” he said, adding that if a security issue is discovered, affected customers will be notified.
“Security at Supabase never ends. We care deeply about doing it right and will continue to ensure all developers ship safely,” said Harmer.
Greg Pollock, a security researcher at UpGuard, said the company’s research is important for raising awareness about the problem of data breaches.
If you make a purchase through links in our articles, we may earn a small commission. This does not affect editorial independence.
