Thousands of Supabase databases are leaking private data to anyone who looks

One of the exposed databases belonged to an African government’s consulate in France. Another was being used by what appears to be a SIM farm to intercept one-time passcodes, the kind of infrastructure typically built for phishing and scams. That’s what’s sitting out on the public web, tied to Supabase, one of the most popular database platforms for developers building apps right now.

According to TechCrunch, cybersecurity firm UpGuard identified roughly 16,000 Supabase-hosted databases with some degree of exposed personal data. The exposed information included names, addresses, phone numbers, user passwords, and authentication tokens. Researchers also found private messages from users of an Indian adult streaming platform, thousands of license plates from a U.S. valet service, and contact details from an immigration and relocation company. These aren’t edge cases. This is a pattern.

Supabase hit a $10 billion valuation earlier this year, largely because developers love it for quickly spinning up apps. Much of that growth has come from the rise of so-called vibe coding, where people use AI tools to generate and deploy apps with minimal technical knowledge. The problem is that speed and convenience don’t pair well with security. AI-generated code can contain flaws, and platforms like Supabase often require specific configuration steps that a non-expert developer may simply not know exist.

This is not a new class of problem. Misconfigured databases and cloud storage buckets have been responsible for some of the most damaging data exposures of the past decade, including leaked military emails, immigration records, and children’s personal data. What’s new is the scale at which AI tools are putting database management into the hands of people who have no background in securing one.

UpGuard’s findings build on earlier research that flagged exposed Supabase databases belonging to Y Combinator startups and other widely used apps. The exposed data appears concentrated in the United States, but UpGuard says this is a global issue.

Supabase’s Chief Information Security Officer Bil Harmer told TechCrunch the company had not seen the research, but said its projects are “secure by default” and that security is a “shared responsibility” between Supabase and its customers. That framing deserves scrutiny. When 16,000 databases are leaking data, pointing to customer misconfiguration is a convenient deflection. A platform that markets itself to non-expert developers has a real responsibility to make dangerous misconfigurations much harder to make in the first place, not just to notify customers after the damage is done.

The exposed datasets in UpGuard’s research include:

  • Private conversations between users and sex workers on an Indian adult streaming site
  • Thousands of vehicle license plates from a U.S. valet service
  • Contact data from an immigration and relocation service
  • Data from an African government’s consulate in France
  • A database used by a virtual SIM farm to intercept one-time passcodes for apparent fraud operations

That last one is worth sitting with. A database used to facilitate scams and phishing attacks was publicly accessible on a platform that just hit a $10 billion valuation. So when Supabase says it “cares deeply about getting it right,” the question is whether caring is enough when the exposure exists at this scale. Real people’s private data is sitting open on the web, and the platform’s response is, essentially, that it told people how to lock the door.