Breaches · 7h ago

UpGuard Finds Supabase Databases Exposing User Data

UpGuard says it found about 16,000 Supabase-hosted databases with some degree of personal data exposed to the public web. The exposed material included names, addresses, phone numbers, user passwords, and in some cases authentication tokens, across apps built on the managed database platform.

The problem is misconfiguration, not a Supabase breach. Developers using hosted or AI-generated apps appear to have left databases reachable from the internet, so the leak surface was the application data itself; once a database is public, the platform can be healthy while the records are not.

That makes the exposure important for teams treating the platform as the security boundary. If a low-code or vibe-coded app stores live customer data there, the lasting risk sits in its access settings and the data it holds, not in any single compromised server.

Timeline

Sources

2 sources covering this story

Part of the PlainSec briefing for 2026-09-28

Editions

Related stories