UpGuard Finds 16,000 Supabase Databases Exposing User Data as AI-Coded Apps Spur Breaches
Updated
Updated · TechCrunch · Sep 25
UpGuard Finds 16,000 Supabase Databases Exposing User Data as AI-Coded Apps Spur Breaches
2 articles · Updated · TechCrunch · Sep 25
Summary
Around 16,000 Supabase-hosted databases were publicly accessible, UpGuard found, exposing personal data including names, addresses, phone numbers, passwords and some authentication tokens.
Basic misconfigurations drove the exposures, with UpGuard saying the boom in AI "vibe-coded" apps is worsening security flaws when developers miss required protections or ship insecure generated code.
The exposed projects spanned an Indian adult streaming site, a U.S. valet service, an immigration and relocation service, an African government's consulate in France and a virtual SIM farm used to intercept one-time passcodes.
Supabase, valued at $10 billion earlier this year, said its projects are secure by default and framed security as a shared responsibility, adding that it notifies affected customers when issues are discovered.
The findings extend earlier reports of exposed Supabase databases and underscore a broader global pattern in which misconfigured cloud services keep leaking sensitive records.