{"id":265210,"date":"2026-09-25T17:29:46","date_gmt":"2026-09-25T17:29:46","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/09\/25\/some-supabase-customers-are-publicly-exposing-reams-of-peoples-data-to-the-web-techcrunch\/"},"modified":"2026-09-25T17:29:46","modified_gmt":"2026-09-25T17:29:46","slug":"some-supabase-customers-are-publicly-exposing-reams-of-peoples-data-to-the-web-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/09\/25\/some-supabase-customers-are-publicly-exposing-reams-of-peoples-data-to-the-web-techcrunch\/","title":{"rendered":"Some Supabase customers are publicly exposing reams of people&#8217;s data to the web | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Thousands of databases hosted by development platform Supabase are exposing people\u2019s sensitive information to the public web, new security research by cybersecurity firm UpGuard has found.<\/p>\n<p class=\"wp-block-paragraph\">UpGuard told TechCrunch that it <a href=\"https:\/\/www.upguard.com\/blog\/everything-everywhere-systemic-data-exposure-in-supabase-apps\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">found around 16,000 databases<\/a> on which some degree of personal data was exposed while they were hosted by Supabase, which allows web and app developers to store and run their databases.<\/p>\n<p class=\"wp-block-paragraph\">Supabase earlier this year <a href=\"https:\/\/techcrunch.com\/2026\/06\/05\/supabase-doubles-valuation-to-10b-in-8-months\/\" target=\"_blank\" rel=\"noopener\">reached a $10 billion valuation<\/a>, thanks to a rise in developers hosting their vibe-coded apps on the platform. But the company has faced criticism for how it handles user security. There are <a href=\"https:\/\/medium.com\/@ctrl_cipher\/how-misconfigured-supabase-apis-exposed-sensitive-data-across-thousands-of-organizations-162e24363c22\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">widely documented<\/a> cases of users <a href=\"https:\/\/deepstrike.io\/blog\/hacking-thousands-of-misconfigured-supabase-instances-at-scale\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">misconfiguring<\/a> or unknowingly exposing their databases to the broader internet, in some instances to the <a href=\"https:\/\/www.wiz.io\/blog\/exposed-moltbook-database-reveals-millions-of-api-keys\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">tune of millions of records each<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">The findings highlight how vibe-coded apps and websites can spill or expose sensitive data through basic misconfigurations and improper security. While AI tools can be used to easily build websites and apps, the generated code can often contain security flaws, or apps might require specific configuration that the developer may be ignorant of.<\/p>\n<p class=\"wp-block-paragraph\">Over the years, countless data breaches have been linked to improperly configured storage servers, databases and websites. Such cases have resulted in the leaks of <a href=\"https:\/\/techcrunch.com\/2024\/02\/14\/department-defense-data-breach-microsoft-cloud-email\/\" target=\"_blank\" rel=\"noopener\">sensitive military emails<\/a>, <a href=\"https:\/\/techcrunch.com\/2026\/05\/27\/uk-visa-portal-spilled-thousands-of-applicants-passports-and-selfies-online-and-hasnt-fixed-the-leak\/\" target=\"_blank\" rel=\"noopener\">immigration and visa applications<\/a>, <a href=\"https:\/\/techcrunch.com\/2017\/11\/28\/army-nsa-inscom-aws-leak\/\" target=\"_blank\" rel=\"noopener\">classified government files<\/a>, <a href=\"https:\/\/techcrunch.com\/2025\/08\/13\/how-we-found-teaonher-spilling-users-drivers-licenses-in-less-than-10-minutes\/\" target=\"_blank\" rel=\"noopener\">hundreds of thousands of driver\u2019s license scans<\/a>, and<a href=\"https:\/\/techcrunch.com\/2026\/01\/20\/ustrive-security-lapse-exposed-personal-data-of-its-users-including-children\/\" target=\"_blank\" rel=\"noopener\"> children\u2019s personal information<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Now, the boom in AI vibe-coding is helping fuel a new wave of data breaches, many of which are now being linked to Supabase as people increasingly use it for storing their data.<\/p>\n<p class=\"wp-block-paragraph\">UpGuard says it sought to understand the scale of exposed data across the platform, and found publicly accessible names, addresses, phone numbers, and user passwords. The research surfaced a fewer number of passwords and authentication tokens.<\/p>\n<p class=\"wp-block-paragraph\">The firm said the databases contained data linked to various projects, such as private conversations with sex workers on an Indian adult streaming site; thousands of license plates of a U.S. valet service; and the contact information of people who used an immigration and relocation service. One of the databases belonged to an African government\u2019s consulate in France, said UpGuard, while another was used to intercept text messages by a virtual SIM farm for sending one-time passcodes to verify online accounts, typically for launching scams and phishing attacks.<\/p>\n<p class=\"wp-block-paragraph\">While the majority of these exposed datasets appear to be located in the United States, UpGuard said this is a worldwide problem. The findings build on earlier research that also found a range of exposed databases hosted on Supabase, including those by <a href=\"https:\/\/modernpentest.com\/blog\/yc-supabase-vulnerability-research\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Y Combinator startups<\/a> and <a rel=\"nofollow noopener\" href=\"https:\/\/www.symbioticsec.ai\/blog\/we-scanned-1-072-vibe-coded-apps-98-had-security-flaws\" target=\"_blank\">other popular apps<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Supabase has <a rel=\"nofollow noopener\" href=\"https:\/\/supaexplorer.com\/dev-notes\/supabase-security-2025-whats-new-and-how-to-stay-secure.html\" target=\"_blank\">made changes<\/a> to its platform over the years, including bolstering its platform and user access to databases. <\/p>\n<p class=\"wp-block-paragraph\">When reached for comment, Supabase\u2019s Chief Information Security Officer Bil Harmer said that while the company has not seen the research, its projects are \u201csecure by default.\u201d He described security as a shared responsibility between the company and its customers. \u201cWe provide secure defaults and tooling, and customers control how their own projects are configured,\u201d and the company notifies affected customers when security issues are discovered, he said. <\/p>\n<p class=\"wp-block-paragraph\">\u201cSecurity at Supabase is never finished. We care deeply about getting it right, and we\u2019ll keep making it easier for every developer to ship securely,\u201d said Harmer.<\/p>\n<p class=\"wp-block-paragraph\">UpGuard security researcher Greg Pollock said the company\u2019s research was important for raising awareness about the issue of data exposures.<\/p>\n<\/div>\n<p><em>When you purchase through links in our articles, <a href=\"https:\/\/techcrunch.com\/techcrunch-affiliate-monetization-standards\/\" target=\"_blank\" rel=\"noopener\">we may earn a small commission<\/a>. This doesn\u2019t affect our editorial independence.<\/em><\/p>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/09\/25\/some-supabase-customers-are-publicly-exposing-reams-of-peoples-data-to-the-web\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Thousands of databases hosted by development platform Supabase are exposing people\u2019s sensitive information to the public web, new security research by cybersecurity firm UpGuard has found. UpGuard told TechCrunch that it found around 16,000 databases on which some degree of personal data was exposed while they were hosted by Supabase, which allows web and app [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":265211,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-265210","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/265210","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=265210"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/265210\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/265211"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=265210"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=265210"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=265210"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}