Tech
Gist from Techcrunch

Massive Data Exposure Crisis Hits Supabase as 16,000 Databases Leak Sensitive Information

Summarized September 25, 2026
Jump to key takeaways

Scale of the Exposure Crisis

Cybersecurity firm UpGuard has uncovered a widespread data exposure problem affecting Supabase, a popular development platform where web and app developers store and manage databases. The research identified approximately 16,000 databases hosted on Supabase containing some degree of publicly exposed personal information. The exposed data includes names, addresses, phone numbers, and user passwords across thousands of instances, representing a significant security vulnerability in one of the industry's fastest-growing platforms. Supabase achieved a $10 billion valuation earlier this year, fueled by its popularity among developers building AI-generated applications.

The Nature of Exposed Information

The breached databases contained highly sensitive information spanning diverse sectors and use cases. UpGuard discovered private conversations from an Indian adult streaming site, thousands of license plate records belonging to a U.S. valet service, contact information for immigration and relocation service users, and data belonging to an African government's French consulate. Particularly troubling was a database operated by a virtual SIM farm that intercepts text messages and one-time passcodes—infrastructure typically used for launching scams and phishing attacks. While the majority of exposed datasets appear to be located in the United States, UpGuard emphasized this represents a global problem affecting organizations worldwide.

Root Cause: AI-Generated Code and Misconfiguration

The security failures stem largely from developers using AI tools to rapidly generate code and build applications without fully understanding the security implications of their configurations. When developers use AI code generation tools to create websites and applications, the generated code frequently contains security flaws or requires specific configuration steps that less experienced developers may overlook. This pattern mirrors broader trends in data breaches over the years—countless incidents have resulted from improperly configured storage servers, databases, and websites. Previous major leaks have exposed sensitive military emails, immigration applications, classified government files, hundreds of thousands of driver's license scans, and children's personal information. The current boom in AI-assisted development is accelerating this problem, with Supabase becoming a focal point as increasing numbers of developers choose the platform for data storage.

Supabase's Response and Security Model

Supabase has made iterative improvements to its platform over time, including security enhancements and expanded user access controls. When contacted for comment, the company's Chief Information Security Officer emphasized that projects are designed to be "secure by default" and characterized security as a shared responsibility between the platform and its customers. The official response framed Supabase's role as providing secure defaults and tooling while customers retain control over their project configurations. The company stated it notifies affected customers when security issues are discovered. However, this shared responsibility model places significant onus on developers—many of whom may lack the security expertise required to properly configure databases and access controls, particularly when using hastily generated AI code.

Ongoing Vulnerability Pattern

This latest research builds on earlier investigations that have also uncovered ranges of exposed databases on Supabase, including some belonging to Y Combinator startups and other prominent applications. The pattern suggests systemic issues extending beyond isolated misconfiguration incidents. Security researcher Greg Pollock from UpGuard characterized the research as important for raising awareness about the prevalence of data exposures. The findings underscore a fundamental tension in modern development: platforms that democratize app building through AI tools simultaneously lower barriers to creating architecturally sound applications while increasing the surface area for security mistakes. As development accelerates and more non-security-focused developers enter the platform, the gap between secure-by-default infrastructure and secure-in-practice deployments continues to widen.

Key Takeaways

  • 16,000 Supabase databases expose names, addresses, passwords publicly
  • AI-generated code lacks security expertise, fueling misconfiguration breaches
  • Exposed data includes government consulate records, SIM farm infrastructure
  • Supabase claims secure-by-default, calls security shared responsibility
  • Problem spans Y Combinator startups and globally distributed services
  • $10 billion platform faces criticism for developer security misconfigurations
  • Rapid AI-assisted development boom accelerating data exposure incidents
Read original article at Techcrunch

Summarize any article in seconds

Gist is a free AI reader for your browser, iPhone, and Android. Get concise summaries and key takeaways from any article or podcast.

Get Gist — Free
⚡ Instant summaries 💬 Chat with articles 🔒 Privacy-first