{"id":257905,"date":"2026-09-25T22:45:44","date_gmt":"2026-09-25T19:45:44","guid":{"rendered":"https:\/\/digitrendz.blog\/z\/?p=257905"},"modified":"2026-09-25T22:45:44","modified_gmt":"2026-09-25T19:45:44","slug":"supabase-data-exposure-customer-errors-expose-public-records","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/tech-news\/257905\/supabase-data-exposure-customer-errors-expose-public-records\/","title":{"rendered":"Supabase Data Exposure: Customer Errors Expose Public Records"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\" open=\"\"><summary>\u25bc Summary<\/summary><p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; Cybersecurity firm UpGuard discovered that approximately 16,000 databases hosted on the Supabase platform were exposing sensitive personal data to the public web.<br>&#8211; The exposed information included names, addresses, phone numbers, passwords, and specific datasets such as license plates and private conversations from various global services.<br>&#8211; This security issue highlights broader risks associated with AI vibe-coding tools, which often generate code containing security flaws or require complex configurations that developers may misunderstand.<br>&#8211; Supabase, a rapidly growing development platform valued at $10 billion, has faced increasing criticism for user misconfigurations leading to significant data breaches over time.<br>&#8211; While the majority of affected datasets originated in the United States, UpGuard emphasizes that this is a worldwide problem stemming from improper security practices across the platform.<br><\/p><\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"has-drop-cap wp-block-paragraph\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0);color:#f34c3e\" class=\"has-inline-color\">T<\/mark>housands of <a href=\"https:\/\/digitrendz.blog\/z\/entity\/supabase\/\" class=\"acp-entity-link\" data-entity-id=\"24730\" data-entity-category=\"Organization\" title=\"Learn more about Supabase\" target=\"_blank\" rel=\"noopener noreferrer\">Supabase<\/a> databases are inadvertently exposing sensitive personal information<\/strong>, according to new security research conducted by cybersecurity firm <a href=\"https:\/\/digitrendz.blog\/z\/entity\/upguard\/\" class=\"acp-entity-link\" data-entity-id=\"116880\" data-entity-category=\"Organization\" title=\"Learn more about UpGuard\" target=\"_blank\" rel=\"noopener noreferrer\">UpGuard<\/a>. The investigation identified approximately <strong>16,000 databases<\/strong> hosted on the platform where some degree of personal data was accessible to the public web. Supabase, a popular development tool that allows web and app creators to store and run their databases, has seen its valuation soar to <strong>$10 billion<\/strong> earlier this year as more developers migrate their &#8220;vibe-coded&#8221; applications to its infrastructure.<\/p>\n\n<p class=\"wp-block-paragraph\">Despite this rapid growth, the company has faced increasing scrutiny over its approach to user security. There are numerous documented instances where users misconfigured their systems or unknowingly left their databases open to the broader internet, resulting in the exposure of millions of records in single incidents. These findings underscore a growing concern regarding how AI-generated code and hastily built websites can spill sensitive data through basic configuration errors. While <a href=\"https:\/\/digitrendz.blog\/z\/tech-news\/256533\/angle-health-valuation-hits-2-7b-as-yc-insurtech-alum\/\" class=\"acp-article-link\" data-article-id=\"256533\" title=\"Angle Health Valuation Hits $2.7B as YC Insurtech Alum\" target=\"_blank\" rel=\"noopener noreferrer\">artificial intelligence<\/a> tools simplify the creation of digital products, the resulting code often contains inherent security flaws, or requires specific settings that inexperienced developers may not understand.<\/p>\n\n<h2 class=\"wp-block-heading\">A History of Misconfiguration Breaches<\/h2>\n\n<p class=\"wp-block-paragraph\">Data breaches linked to improperly configured storage servers, databases, and websites have been a persistent issue for years. Such vulnerabilities have previously led to the leak of sensitive military communications, immigration and visa applications, classified government documents, hundreds of thousands of driver\u2019s license scans, and personal information belonging to children. The current surge in AI-driven vibe-coding is fueling a new wave of these breaches, with many recent incidents now tied directly to Supabase as it becomes the preferred backend for storing application data.<\/p>\n\n<p class=\"wp-block-paragraph\">UpGuard\u2019s research aimed to quantify the scale of exposed data across the platform. The study revealed publicly accessible names, addresses, phone numbers, and user passwords, along with a smaller number of authentication tokens. The exposed databases contained highly sensitive information from diverse projects. These included private conversations involving sex workers on an <a href=\"https:\/\/digitrendz.blog\/z\/entity\/indian-adult-streaming-site\/\" class=\"acp-entity-link\" data-entity-id=\"301465\" data-entity-category=\"facility\" title=\"Learn more about Indian adult streaming site\" target=\"_blank\" rel=\"noopener noreferrer\">Indian adult streaming site<\/a>, thousands of license plates from a U. S. valet service, and contact details for individuals using an immigration and relocation service. Additionally, one database belonged to an African government\u2019s consulate in <a href=\"https:\/\/digitrendz.blog\/z\/entity\/france\/\" class=\"acp-entity-link\" data-entity-id=\"1697\" data-entity-category=\"Location\" title=\"Learn more about France\" target=\"_blank\" rel=\"noopener noreferrer\">France<\/a>, while another was utilized by a virtual SIM farm to intercept text messages containing one-time passcodes, typically for launching scams and phishing attacks.<\/p>\n\n<h2 class=\"wp-block-heading\">Shared Responsibility and Platform Security<\/h2>\n\n<p class=\"wp-block-paragraph\">Although the majority of these exposed datasets appear to be located in the United States, UpGuard emphasized that this is a global issue. The findings expand upon earlier research that also identified a range of exposed databases on Supabase, including those belonging to <a href=\"https:\/\/digitrendz.blog\/z\/entity\/y-combinator\/\" class=\"acp-entity-link\" data-entity-id=\"4236\" data-entity-category=\"Organization\" title=\"Learn more about Y Combinator\" target=\"_blank\" rel=\"noopener noreferrer\">Y Combinator<\/a> startups and other well-known applications. In response to ongoing concerns, Supabase has implemented changes to its platform over the years, aiming to bolster security measures and improve user access controls for databases.<\/p>\n\n<p class=\"wp-block-paragraph\">When contacted for comment, Supabase\u2019s Chief Information Security Officer <a href=\"https:\/\/digitrendz.blog\/z\/entity\/bil-harmer\/\" class=\"acp-entity-link\" data-entity-id=\"301463\" data-entity-category=\"Person\" title=\"Learn more about Bil Harmer\" target=\"_blank\" rel=\"noopener noreferrer\">Bil Harmer<\/a> stated that the company had not yet reviewed the specific research but maintained that its projects are <strong>\u201csecure by default.\u201d<\/strong> He characterized security as a shared obligation between the provider and its users. <strong>\u201cWe provide secure defaults and tooling, and customers control how their own projects are configured,\u201d<\/strong> Harmer explained, noting that the company notifies affected customers when security issues are discovered.<\/p>\n\n<p class=\"wp-block-paragraph\">Harmer further emphasized the company\u2019s commitment to continuous improvement in safety protocols. <strong>\u201cSecurity at Supabase is never finished. We care deeply about getting it right, and we\u2019ll keep making it easier for every developer to ship securely,\u201d<\/strong> he said. UpGuard security researcher Greg Pollock noted that the firm\u2019s research was crucial for raising awareness about the pervasive problem of data exposures in modern development environments.<\/p>\n\n<em>(Source: <a href='https:\/\/techcrunch.com\/2026\/09\/25\/some-supabase-customers-are-publicly-exposing-reams-of-peoples-data-to-the-web\/' target='_blank'>TechCrunch<\/a>)<\/em>","protected":false},"excerpt":{"rendered":"<p>UpGuard research revealed that approximately 16,000 Supabase databases are inadvertently exposing sensitive personal information to the public web. This issue highlights growing security concerns as AI-generated code and rapid development practices often lead to basic configuration errors. The ex&#8230;<\/p>\n","protected":false},"author":1,"featured_media":257904,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[57,3247,3297,3327,3254],"tags":[258427,250801,128572,3362,258426],"entities":[258428,1354,258429,17262,3271,82197,3672,3351],"class_list":["post-257905","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech-news","category-artificial-intelligence","category-cybersecurity","category-newswire","category-technology","tag-bil-harmer","tag-france","tag-supabase","tag-techcrunch","tag-upguard","entity-bil-harmer","entity-france","entity-indian-adult-streaming-site","entity-supabase","entity-techcrunch","entity-upguard","entity-us","entity-y-combinator"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/257905","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=257905"}],"version-history":[{"count":0,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/257905\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/257904"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=257905"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=257905"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=257905"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=257905"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}