Certain Supabase Users Are Unintentionally Leaking Vast Amounts of Personal Data Online

Recent security analysis by UpGuard has revealed that numerous databases managed by the development platform Supabase are unintentionally exposing sensitive personal information online.
According to UpGuard, approximately 16,000 databases have been identified as having some form of personal data publicly accessible while hosted by Supabase, a platform used by developers to manage and store their databases for web and app projects.
Earlier this year, Supabase achieved a valuation of $10 billion, spurred by an increase in developers utilizing the platform for their applications. However, the company has faced scrutiny regarding its user security practices, especially given the number of users who have poorly configured their databases, leading to significant data exposures, sometimes involving millions of records.
These findings emphasize the risks associated with poorly configured apps and websites, particularly as AI tools simplify the website and app creation process. Unfortunately, the code generated by such tools can often harbor security vulnerabilities, and developers may lack the expertise to properly configure their applications.
Over the years, numerous data breaches have been traced back to incorrectly configured storage solutions, databases, and websites. These incidents have revealed sensitive materials, including classified government documents, military communications, immigration records, and the personal data of minors.
The increasing trend of AI-assisted coding is contributing to a surge in data leaks, many of which are being associated with Supabase as more users turn to it for data storage.
UpGuard aimed to assess the extent of public data exposure on the platform and discovered records containing names, addresses, phone numbers, and user passwords. The research also uncovered a smaller quantity of authentication tokens and passwords.
Among the exposed data were sensitive details related to various projects, including private discussions from an adult streaming service in India, numerous license plate numbers from a U.S. valet service, and contact details of users from an immigration and relocation agency. Additionally, one of the databases belonged to a French consulate representing an African government, while another was used to intercept messages for one-time passcodes, often linked to online scams and phishing schemes.
While the majority of exposed databases are found in the U.S., UpGuard indicated that this issue has global implications. The recent findings add to prior research that highlighted various vulnerable databases hosted on Supabase, including those from prominent Y Combinator start-ups and other well-known applications.
Supabase has implemented several changes over the years aimed at improving security on its platform, enhancing user access controls for databases.
In response to the research, Supabase’s Chief Information Security Officer, Bil Harmer, stated that the company has not directly reviewed the findings but maintains that its projects are designed to be secure by default. He highlighted that security responsibilities are shared between the company and its users, asserting that while Supabase provides secure defaults and tools, customers have control over their project configurations. Harmer mentioned that the company informs users when vulnerabilities are detected.
“Security at Supabase is an ongoing commitment. We are dedicated to refining our practices to ensure developers can launch projects securely,” Harmer said.
UpGuard’s security researcher, Greg Pollock, emphasized that the purpose of their research is to elevate awareness surrounding data exposure risks.



