tech
What We Know About the Supabase Data Exposure Findings

Security researchers reported that thousands of databases hosted on the development platform Supabase are publicly exposing people's personal information because of misconfigured access settings, according to TechCrunch's report on findings from cybersecurity firm UpGuard, published Sept. 25, 2026.
What did UpGuard find?
UpGuard reported identifying about 16,000 Supabase-hosted databases where some degree of personal data was publicly accessible, according to research the firm shared with TechCrunch. The exposed records included names, addresses and phone numbers, along with a smaller number of user passwords and authentication tokens, the outlet reported.
Why are these databases visible on the open internet?
Supabase lets web and app developers store and run databases for their projects. TechCrunch reported that some customers have misconfigured or unknowingly exposed those databases to the broader internet, in certain cases affecting millions of records tied to a single project. The outlet linked the pattern to a rise in AI-generated, or "vibe-coded," apps, noting that generated code can contain security flaws or require configuration steps that developers may not apply correctly.
What kinds of data and projects were affected?
According to TechCrunch's account of the UpGuard research, exposed datasets included private conversations tied to sex workers on an Indian adult streaming site, thousands of license plates logged by a U.S. valet service, and contact details collected by an immigration and relocation service. One database belonged to an African government's consulate in France, and another was tied to a virtual SIM farm intercepting one-time passcodes commonly used in scam and phishing schemes, the report said. UpGuard told the outlet most of the exposed data appears concentrated in the United States but described the issue as a worldwide problem.
Has Supabase faced this kind of exposure before?
Yes. TechCrunch reported that the new findings build on earlier research documenting exposed Supabase databases tied to Y Combinator-backed startups and other applications. The company reached a $10 billion valuation earlier this year amid growth in developers hosting AI-generated apps on the platform, according to the outlet, which has also faced scrutiny over how it handles user security.
What has Supabase said in response?
The sourced TechCrunch report does not include a detailed, on-the-record statement from Supabase addressing UpGuard's specific findings. The article notes only that the company has taken some action, without elaborating further in the material reviewed for this piece.
What should developers and users watch for next?
- Whether Supabase publishes updated default security settings or runs its own audit of public-facing projects.
- Whether organizations named in UpGuard's findings, including the consulate and immigration-service projects, notify affected individuals directly.
- Whether independent researchers replicate UpGuard's scan and report a different total exposure count.
- Whether any regulator opens an inquiry tied to the specific cases UpGuard flagged, such as the SIM-farm database linked to one-time-passcode interception.
The method behind the 16,000 figure — UpGuard's scanning approach and how it verified personal data versus other exposed content — was not detailed in the TechCrunch report, and no sample size or methodology paper was cited in the material available.
Questions
How many Supabase databases did UpGuard find exposed?
UpGuard reported finding roughly 16,000 Supabase-hosted databases with some degree of personal data publicly accessible, according to TechCrunch.
What kind of data was exposed?
TechCrunch reported the exposed data included names, addresses, phone numbers, and in fewer cases, passwords and authentication tokens.
Why does this keep happening on Supabase?
TechCrunch linked the exposures to developer misconfiguration, often in AI-generated or 'vibe-coded' apps where security settings require manual setup that some developers skip.