UpGuard says around 16,000 Supabase databases exposed personal data

Security researcher UpGuard reported that around 16,000 databases hosted on Supabase were publicly exposing at least some personal data. The firm said the exposed information included names, addresses, phone numbers, user passwords and a smaller number of authentication tokens.

Scope and examples of exposed data

UpGuard said the datasets were linked to a range of projects and contained sensitive records. Examples cited by the firm include private conversations with sex workers on an Indian adult streaming site; thousands of license plates from a U.S. valet service; and contact information for users of an immigration and relocation service.

The research also flagged a database tied to an African government’s consulate in France and another used by a virtual SIM farm that intercepted text messages for one‑time passcodes, which UpGuard said are typically abused in scams and phishing attacks. While the majority of exposed datasets appeared to be located in the United States, UpGuard described the problem as worldwide.

Context and platform response

Supabase, which earlier this year reached a $10 billion valuation, provides database hosting for many web and app developers, including those who use AI-generated or “vibe-coded” apps. UpGuard warned that generated code and default configurations can lead to inadvertent exposures when developers are unaware of required security settings.

Supabase Chief Information Security Officer Bil Harmer told reporters the company had not seen the research but described Supabase projects as “secure by default.” Harmer said security is “a shared responsibility between the company and its customers,” adding, “We provide secure defaults and tooling, and customers control how their own projects are configured.” He also said the company notifies affected customers when security issues are discovered and that “Security at Supabase is never finished. We care deeply about getting it right, and we’ll keep making it easier for every developer to ship securely.”

UpGuard security researcher Greg Pollock said the research was important for raising awareness about data exposures. The firm’s findings follow earlier work that uncovered additional exposed databases on Supabase and other hosting providers.


Original source: TechCrunch AI

Leave a Comment