UpGuard, a cyber risk company, has found 16,326 databases hosted on Supabase whose tables can be read by anyone on the internet, and a substantial share of them hold personal details, passwords or login tokens. The researchers examined roughly 300,000 domains that showed signs of running on the popular back-end platform before counting the exposures, and the tally covers organizations as different as a valet company, a consulate and an immigration service.
The cause, according to the report, is not a break-in at Supabase itself but missing or weak access rules on the apps built on top of it. Supabase says its projects are secure by default, and it puts the responsibility for configuration on the customers who build them.
What UpGuard scanned and what it found
UpGuard’s research, published September 25 in a report called “Everything Everywhere” and written by Greg Pollock, the company’s director of research and insights, used BuiltWith and Chrome UX Report data to identify Supabase deployments. The team then queried for tables named “users” and judged what each database exposed from its schema rather than by downloading records in bulk, an approach that lets a researcher classify the type of data at risk without copying the data itself. Over half of the 16,326 exposed databases showed signs of personally identifiable information, and a smaller percentage included passwords or authentication tokens.
BleepingComputer, which summarized the findings on September 28, described “more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens.” A limited number of databases also showed indicators of credit card data, judged from table structure.
Cases UpGuard disclosed
The report walks through several examples. A U.S. valet service exposed more than 100,000 customer records with contact details, license plates and visit histories, the kind of data that ties a named person to a vehicle and a place. A Canadian immigration service exposed nearly 5,000 user records, 884 of them with plaintext passwords. An African government consulate exposed records on 25,000 people, including addresses and emergency housing locations.
Other cases were more personal. A creator platform based in India exposed identity and payment details along with more than 100,000 private messages, and UpGuard counted 65,467 users affected. A Philippines-based one-time-password service exposed more than 2,000 user records and 100,000 SMS messages, and TechCrunch reported that one database appeared to have been used for intercepting text messages through virtual SIM farms tied to scam operations.
The kinds of sites involved varied. According to Cybernews, e-commerce and restaurant apps most often exposed personal information and payment systems, while unlicensed betting platforms commonly leaked passwords and credentials. Misconfigurations were also found worldwide, and UpGuard said developing regions showed higher concentrations of leaks than Europe, where it credited data protection laws with driving better practices.
Row-level security, vibe coding and who is responsible
The technical fault BleepingComputer cited is “missing or ineffective row-level security policies and misuse of public keys.” Supabase’s documentation is blunt about the risk: “A table in an exposed schema without RLS is readable and writable by any role with a grant on it. Enable RLS on every table in an exposed schema.” A public key meant to be embedded in a website is harmless only when those rules are in place; without them, the same key opens the table to any visitor. The documentation adds that on existing projects a new table in the public schema “starts with every privilege already granted” to the anonymous role and that “adding policies doesn’t take those grants back,” which means the fix is to turn security on deliberately for each table rather than to assume it is already on.
UpGuard tied part of the problem to AI-assisted coding. BleepingComputer reported that AI-assisted development accounts for more than 60 percent of newly created databases, while acknowledging that not every affected site necessarily used an AI coding agent. UpGuard’s own wording, as quoted by BleepingComputer, was that “humans who know their business do not understand their database’s configuration.” Cybernews similarly linked the exposures to apps built with tools such as Lovable.
Supabase’s chief information security officer, Bil Harmer, told TechCrunch that projects are “secure by default” and that security is a shared responsibility between the company and its customers. The company provides secure defaults and tooling, he said, while “customers control how their own projects are configured.”
For developers already running on the platform, BleepingComputer said the advice is to review Supabase’s security documentation, including its security advisors and API security guides, and to confirm that every table reachable through a public key has row-level security policies that limit what a visitor can read or change.
The two positions leave open who should be closing the gap for the thousands of apps already exposed, and neither UpGuard’s report nor Supabase’s statement says how many of the 16,326 databases have been secured since the scan.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Early electric-car owners are hitting battery and screen failures no one warned them about
- A magnitude 5.3 quake struck off the Oregon coast this week
- Amazon’s Prime refunds are rising to $200 as millions more customers become eligible
- A handful of car engines are so tough mechanics say they almost never wear out