Skip to main content
Emerging ThreatsData Breaches

Misconfigured Supabase Apps Expose Data in 16,000 Databases

Rows of computer servers and storage devices in a brightly-lit data center with cables on the floor and a blurred console…

"The security settings are invariant to business type because the humans, who know what kind of business they are advertising, do not understand their database’s configuration," UpGuard wrote after analyzing widespread leaks tied to Supabase deployments.

UpGuard's sweep: scope and method

Researchers at cyber risk management company UpGuard examined a dataset of roughly 300,000 domains that showed signs of using Supabase and attempted to locate a 'users' table across those services. Their scan focused on table-level access: some queries returned full pages from databases, while other queries suggested that a differently named table was accessible instead of a canonical 'users' table. By analyzing table schemas, the team inferred the kinds of data exposed across the collection of reachable databases.

What was exposed: PII, passwords, tokens — and a small amount of payment data

UpGuard concluded that more than 16,000 misconfigured Supabase databases exposed readable tables. In over half of those exposed databases the researchers identified personally identifiable information (PII). A smaller subset contained passwords and authentication tokens. Based on the table-schema analysis, UpGuard believes that only a very small set of the exposed information includes credit card data.

Representative breaches found during the analysis

UpGuard catalogued several high-impact findings that illustrate the range of services affected and the kinds of data left readable:

  • A U.S. valet service exposed more than 100,000 customer records, including contact details, license-plate information, and visit history.
  • A Canadian immigration service dataset contained nearly 5,000 user records, including 884 plaintext passwords.
  • An India-based adult creator platform revealed sensitive identity and payment-account information, and more than 100,000 private messages.
  • A Philippines-based one-time-password (OTP) service exposed data on more than 2,000 users and approximately 100,000 SMS messages, which included some apparently unrelated person-to-person communications.
  • An African government consulate exposed records for 25,000 people that included addresses and emergency housing locations.

Root causes identified: configuration, row-level security, and public keys

UpGuard attributed the exposures to poor application security configurations. The researchers highlighted missing or ineffective row-level security policies and misuse of public keys as primary contributors to data availability. They also raised the role of development practices: Supabase's open-source platform has seen rapid uptake, and the company’s tools are frequently used to accelerate app delivery.

UpGuard further reported that AI-assisted development accounted for more than 60% of newly created databases in the environments the team examined, and suggested that the common thread among exposed sites was a lack of human understanding of the deployed database configuration. At the same time, the researchers cautioned that their scans do not establish that every affected site was built using an AI coding agent.

What this means for Supabase users, technologists, and end users

  • Supabase users and application owners: UpGuard said it notified application owners when its deeper analysis identified significant exposure and urged users to review Supabase’s security documentation, including the platform’s advisors and API security guide, to identify and mitigate exposure risks.
  • Technologists and security teams: the findings underscore the importance of applying effective row-level security and correct key management. UpGuard’s method—schema inspection across a large domain set—demonstrates how configuration mistakes can be identified at scale.
  • End users and customers of affected services: records found in the scan included contact details, authentication credentials, license-plate and visit histories, messages, and emergency-housing locations; where plaintext passwords or authentication tokens are present, the risk of account takeover or downstream abuse rises unless remediated.

UpGuard’s analysis paints a picture of a modern development ecosystem where ease of deployment can outpace secure configuration. The concrete findings—tens of thousands of exposed records across services from valet companies to government consulates—underscore that the technical fix is familiar even if the pattern of exposure is new: ensure effective row-level security, limit public key misuse, and validate database access controls. UpGuard’s disclosure practice—alerting owners when significant exposure was found and pointing users toward Supabase’s security guides—sets a narrow but immediate path for remediation. Whether that path will close the gap between rapid application creation and secure configuration remains the urgent operational question left by these scans.

Original report