UpGuard has identified approximately 16,000 Supabase databases containing personal information that are accessible to the public internet.
In this article
The cybersecurity firm discovered these exposures while scanning the platform used by developers to host their applications. This comes shortly after Supabase reached a $10 billion valuation earlier this year, a milestone driven by the surge in developers using the service for apps built with artificial intelligence.
The problem with generated code
Recent security incidents show that websites and applications created through AI tools frequently contain flaws or require specific settings that developers do not understand. When these applications are launched, sensitive data can spill out through basic configuration errors.
History shows that improperly set up storage servers and databases have previously led to leaks of military emails, immigration applications, classified government files, hundreds of thousands of scanned driver’s licences, and children’s private details.
The current boom in AI-assisted coding is fueling a new wave of such breaches. As more people rely on Supabase to store their data, the number of exposed records is rising.
What was exposed
UpGuard’s research uncovered publicly available names, addresses, phone numbers, and user passwords. There were fewer instances of exposed passwords and authentication tokens.
The datasets included a wide variety of sensitive information. Records linked to private conversations between sex workers and clients on an Indian adult streaming site were found. Thousands of vehicle registration plates belonging to a US valet service were also made public.
Contact details for people using an immigration and relocation service were exposed. UpGuard noted one database belonged to an African government consulate in France. Another was used by a virtual SIM farm to intercept text messages containing one-time passcodes, a method typically used to verify online accounts for scams and phishing attacks.
Although most of these datasets appear to be located in the United States, the firm describes the issue as global. The findings extend earlier research that identified exposed databases hosted on Supabase, including those belonging to Y Combinator startups and other popular applications.
Supabase response
The company has made changes to its platform over the years to improve security and user access to databases. When contacted, Supabase Chief Information Security Officer Bil Harmer stated the company had not seen the specific research.
He said the company’s projects are secure by default. Harmer described security as a shared responsibility. The firm provides secure defaults and tools, while customers control how their own projects are configured. He added that the company notifies affected customers when security issues are discovered.
“Security at Supabase is never finished,” Harmer said. “We care deeply about getting it right, and we’ll keep making it easier for every developer to ship securely.”
Greg Pollock, a security researcher at UpGuard, said the company’s research was important for raising awareness about the issue of data exposures.




