Thousands of Supabase databases leak user data online

Thousands of Supabase databases leak user data online

Thousands of Supabase databases leak user data online
Research from UpGuard reveals widespread data exposure affecting thousands of Supabase customers, putting personal information at risk on the public web.
Supabase data exposure

Thousands of Supabase Databases Are Leaking Sensitive Personal Information

A major security vulnerability affecting developers has just surfaced. Cybersecurity researchers at UpGuard discovered approximately 16,000 databases hosted on Supabase that are publicly exposing sensitive personal information to anyone on the internet. This isn’t a hack or a sophisticated attack—it’s misconfiguration, and it’s happening at scale.

The exposed data includes names, home addresses, phone numbers, passwords, and authentication tokens. Some databases contained far more alarming information: private conversations from adult streaming platforms, license plate numbers from valet services, contact details from immigration and relocation agencies, and even records used to intercept text messages for account takeover scams.

For developers using Supabase—a backend-as-a-service platform that lets teams quickly build and host databases without managing infrastructure—this discovery raises serious questions about default security settings and how easy it is to accidentally expose user data.

How This Supabase Data Exposure Happened

The problem stems from a combination of factors that have become increasingly common as more developers rely on AI-assisted code generation to build applications quickly. When developers use AI tools to generate code for web and mobile apps, the generated code often contains security flaws or requires specific configurations that many developers simply aren’t aware of.

Supabase provides database hosting and APIs, but configuring proper access controls falls on the developer. When those configurations aren’t set correctly, databases become publicly accessible. The research team found that many of these exposed databases weren’t deliberately published—developers simply didn’t realize they needed to restrict access.

One database belonged to an African government’s consulate in France. Another was used by a virtual SIM farm to intercept text messages, enabling one-time passcode theft for account takeover attacks. The scope of exposure reveals how this issue affects organizations across sectors and countries, though the majority of exposed datasets were located in the United States.

The Role of AI-Generated Code in Database Misconfigurations

As artificial intelligence tools make it easier for people without deep security knowledge to build functional applications, they’re simultaneously making it easier to ship insecure code at scale. Developers using AI to quickly prototype or launch apps may not understand the security implications of their configurations.

This mirrors a larger trend in the industry. Previous research on AI-generated applications found that 98% of vibe-coded apps contained security flaws. The problem isn’t unique to Supabase—misconfigured databases and storage systems have caused leaks involving millions of records, including classified government files, military emails, and driver’s license scans.

But the rising popularity of Supabase among startups and individual developers means more inexperienced teams are using the platform. When the company reached a $10 billion valuation earlier this year, much of that growth came from developers choosing Supabase for quick development cycles. That explosive growth has outpaced security awareness among some users.

What Supabase Says About Security

Supabase’s Chief Information Security Officer responded to the research by emphasizing that the platform is “secure by default” and that security is a shared responsibility between the company and its customers. He stated that Supabase provides secure defaults and tooling, while customers control their own project configuration.

The company has made security improvements over time, including bolstering platform security and refining user access controls to databases. Supabase also notifies customers when security issues are discovered.

However, the “secure by default” claim doesn’t fully address the core issue: even with secure defaults, developers must still actively configure access controls. Many developers don’t know these configurations exist or understand why they matter until after a breach occurs.

Real Examples of Exposed Data from This Research

The UpGuard findings paint a detailed picture of what’s actually at risk. One exposed database contained thousands of license plate numbers from a U.S. valet service. Another held contact information for people using immigration and relocation services. A third was used for private conversations on an adult streaming platform.

Beyond personal information, some exposed databases contained authentication tokens and passwords, making them extremely valuable to attackers. A database associated with a virtual SIM farm stands out as particularly dangerous—these operations intercept one-time passcodes to hijack accounts on banking, social media, and email platforms.

This research builds on previous findings that identified exposed databases among Y Combinator startups and other popular applications built on Supabase. The pattern is clear: this isn’t an isolated incident but a systemic issue affecting how developers configure database access.

What Developers Need to Know Right Now

If you’re building applications on Supabase or any similar platform, security configuration isn’t optional—it’s essential. Before deploying any project, verify that your database access policies restrict data to authenticated users only. Don’t rely on the assumption that “secure by default” means your application is automatically secure.

Review your project’s Row-Level Security (RLS) policies and API authentication settings. If you’re using AI tools to generate application code, treat the output as a starting point, not a finished product. Security requires additional steps and deliberate choices.

For teams using Supabase, the company recommends enabling authentication on your APIs, setting appropriate Row-Level Security policies, and regularly auditing which databases and tables are accessible. Documentation on these topics exists, but it requires developers to seek it out and implement it correctly.

Common Questions About This Supabase Data Exposure Issue

Is Supabase itself to blame for this exposure? Supabase provides the infrastructure and tools, but developers must configure access controls. The company argues this is shared responsibility, though security researchers point out that better default settings or more prominent warnings during setup could prevent many of these exposures.

Will I be notified if my data was exposed? Supabase says it notifies customers when security issues are discovered. However, if your application data was exposed through misconfiguration, you may not hear about it unless you’re actively monitoring your own database access logs or a security firm discovers it.

Should I stop using Supabase? Supabase itself isn’t inherently unsafe. The issue is that any developer-controlled database platform requires proper configuration. The key is understanding your responsibility for security and taking the time to implement proper access controls before deploying to production.

For developers who’ve built applications on Supabase, now is the time to audit your security settings. Check your authentication requirements, verify Row-Level Security policies are enabled, and ensure your API keys are properly restricted. The security improvements Supabase continues to make help, but they can’t replace deliberate configuration on your end.

Scroll to Top