← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Supabase databases expose sensitive user data due to misconfigurations, UpGuard research finds

🔄 Updated 5h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • UpGuard found 16,000 Supabase databases publicly exposing personal data.
  • Exposed data included names, addresses, phone numbers, and passwords.
  • Misconfigurations by developers are cited as the primary cause.
  • Supabase has faced criticism regarding its user security practices.

Thousands of Databases Exposed

Cybersecurity firm UpGuard has identified approximately 16,000 databases hosted by development platform Supabase that are publicly exposing sensitive personal information. This includes data such as names, addresses, phone numbers, and user passwords. The research indicates that while some passwords and authentication tokens were found, the primary concern is the broad exposure of personal identifiers.

Developer Misconfigurations as Root Cause

The exposure is attributed to misconfigurations by developers using the Supabase platform. The ease of building applications, sometimes with AI tools, can lead to security flaws in generated code or a lack of understanding regarding necessary security configurations. This issue is not unique to Supabase, as improperly configured storage servers and databases have historically led to numerous data breaches.

Supabase's Security Challenges

Supabase, which recently achieved a $10 billion valuation, has faced criticism regarding its approach to user security. There are documented instances of users unknowingly exposing their databases to the internet, sometimes involving millions of records. The platform allows developers to store and run their databases, and the current findings underscore ongoing challenges in ensuring data privacy and security for its users.

Examples of Exposed Data

UpGuard's research uncovered various types of sensitive data across different projects. Examples include private conversations from an Indian adult streaming site, thousands of license plates from a U.S. valet service, and contact information from an immigration and relocation service. One database belonged to an African government's consulate in France, and another was linked to a virtual SIM farm used for intercepting text messages for one-time passcodes, often associated with scams and phishing.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~17 min · 13 stories · Sep 25

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Cybersecurity firm UpGuard discovered approximately 16,000 Supabase-hosted databases publicly exposing personal data, including names, addresses, phone numbers, and passwords. This exposure stems from common misconfigurations by developers, highlighting security risks associated with rapidly developed applications and the platform's handling of user security.