Friday, 25 September 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 25 September 2026 at 20:45

Researchers find thousands of exposed Supabase databases leaking personal data

Cybersecurity firm UpGuard has identified around 16,000 Supabase-hosted databases exposing people's personal information due to misconfigurations. Supabase says security is a shared responsibility between the company and its customers.

Foto: TechCrunch AI

Cybersecurity firm UpGuard has found that roughly 16,000 databases hosted on the developer platform Supabase are exposing sensitive personal information to the public internet to some degree. Supabase lets web and app developers store and run their databases, and the company reached a $10 billion valuation this year, driven by growing numbers of developers hosting AI-generated, or "vibe-coded," apps on the platform.

Misconfigurations expose data

There have long been documented cases of users misconfiguring or unknowingly leaving their databases open, sometimes exposing millions of records at once. UpGuard's research uncovered publicly accessible names, addresses, phone numbers and user passwords, along with a smaller number of authentication tokens. Among the exposed data were private conversations from an Indian adult streaming site, thousands of license plates from a U.S. valet parking service, contact details of customers from an immigration and relocation service, and records belonging to an African government's consulate in France. Another database was reportedly used to intercept one-time passcodes, likely tied to scam operations.

Vibe-coding and security risks

Most of the exposed data was traced to the United States, though UpGuard says the issue is a global one. The firm notes that AI-generated code frequently contains security flaws or requires specific configuration that developers may not be aware of, contributing to a new wave of data breaches tied to Supabase's growing popularity.

Supabase's chief information security officer, Bil Harmer, said the company had not seen the specific research but maintained that its projects are secure by default. He described security as a shared responsibility between Supabase and its customers, who control how their own projects are configured, adding that the company notifies affected customers when issues are found.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category