UpGuard identifies 16,000 publicly exposed Supabase databases

UpGuard finds widespread public exposure on Supabase
Cybersecurity firm UpGuard says it identified around 16,000 databases hosted on development platform Supabase that exposed some degree of personal information to the public web. The accessible records included names, addresses, phone numbers and user passwords, while a smaller number of databases exposed passwords and authentication tokens.
Supabase provides database hosting and related services for web and application developers. Its rapid growth has coincided with broader use of AI-assisted “vibe coding”, where developers use AI tools to create applications and websites. The research highlights how generated code, insecure settings or overlooked configuration requirements can leave data available to anyone online.
Exposed datasets covered varied projects
UpGuard said its research found data associated with a wide range of projects. Examples included private conversations with sex workers on an Indian adult streaming site, thousands of licence plates held by a US valet service, and contact details submitted to an immigration and relocation service.
The firm also identified a database belonging to an African government’s consulate in France. Another database was used by a virtual SIM farm to intercept text messages carrying one-time passcodes, which can be used to verify online accounts and are commonly associated with scam and phishing activity.
Although most of the datasets appeared to be in the United States, UpGuard described the issue as global. The findings follow other research into publicly accessible Supabase databases, including databases associated with Y Combinator startups and popular applications.
Shared responsibility and configuration controls
Supabase Chief Information Security Officer Bil Harmer said the company had not seen UpGuard’s research, but maintained that its projects are secure by default. He described security as a shared responsibility: Supabase provides secure defaults and tools, while customers decide how their projects are configured.
Harmer said Supabase notifies affected customers when it discovers security issues and continues to make it easier for developers to deploy securely. The platform’s scale is also reflected in Supabase’s $10 billion valuation after funding, which details its $10 billion valuation after a $500 million funding round.
UpGuard researcher Greg Pollock said the work was intended to raise awareness of data exposure. For businesses using Supabase or comparable managed database platforms, the practical implication is to review public access rules, authentication settings and permissions before release, and to retest them whenever an application or its configuration changes.

