16,000 Supabase Databases Left Exposed Online
Security researchers identified widespread misconfigurations in databases that left sensitive user data publicly accessible.
Updated on Sept. 25, 2026 in Cybersecurity

Live Poll
Do you trust technology platforms to secure your personal data by default?
Security firm UpGuard identified 16,000 databases hosted on the Supabase platform that were inadvertently left accessible to the public. These exposed datasets contain personal information including user names, addresses, phone numbers, and passwords.
Why it matters
The findings highlight growing security risks as AI-assisted coding tools accelerate application development without ensuring necessary infrastructure configurations. Developers may lack the expertise to secure these environments, leading to significant vulnerabilities.
UpGuard identified 16,000 exposed instances, including one database containing a virtual SIM farm used to intercept text messages. Supabase operates on a shared responsibility model, placing the burden of database configuration on the customer.
The players
UpGuard
A cybersecurity company that specializes in monitoring digital footprints and identifying data exposures in cloud environments.
Supabase
An open-source Firebase alternative that provides backend-as-a-service tools, including managed PostgreSQL databases.
The details
The exposures occurred primarily due to user misconfigurations or oversights when deploying applications. Developers often utilize AI-generated code that may contain security flaws or require specific configuration settings that users are not equipped to manage. This creates a scenario where databases, including those belonging to an Indian adult streaming site and an African government consulate in France, remained open to the public internet.
Timeline
2026: Supabase achieved a valuation of $10 billion.
September 25, 2026: TechCrunch reported on the UpGuard security findings.
The Tech Race
This incident follows a recurring pattern established by the 2019 Capital One data breach, where misconfigured cloud-based infrastructure leads to the widespread exposure of sensitive user data. It underscores the challenges platforms face as they prioritize rapid deployment tools over secure-by-default configurations.
Users should monitor their accounts for suspicious activity, as exposed data included passwords and phone numbers capable of facilitating phishing attacks. Developers using platform-as-a-service tools must verify their specific database permission settings immediately.
The takeaway
The event serves as a reminder that managed cloud services do not eliminate the need for manual security configuration by the end user. Developers should audit their infrastructure settings to ensure sensitive data is not publicly accessible.
Further reading
For more information on securing cloud-hosted environments, visit the Cybersecurity section.
Live Poll
Do you trust technology platforms to secure your personal data by default?







