16,000 Supabase Databases Left Exposed Online

Security researchers identified widespread misconfigurations in databases that left sensitive user data publicly accessible.

Updated on Sept. 25, 2026 in Cybersecurity

Isometric editorial illustration of dark server rack cabinets and network conduits, representing large-scale digital infrastructure vulnerability.
Security researchers at UpGuard discovered 16,000 misconfigured databases on the Supabase platform, exposing sensitive user records including passwords and contact details online. AI Illustration. Upload story photo >

Live Poll

Do you trust technology platforms to secure your personal data by default?

Security firm UpGuard identified 16,000 databases hosted on the Supabase platform that were inadvertently left accessible to the public. These exposed datasets contain personal information including user names, addresses, phone numbers, and passwords.

Why it matters

The findings highlight growing security risks as AI-assisted coding tools accelerate application development without ensuring necessary infrastructure configurations. Developers may lack the expertise to secure these environments, leading to significant vulnerabilities.

UpGuard identified 16,000 exposed instances, including one database containing a virtual SIM farm used to intercept text messages. Supabase operates on a shared responsibility model, placing the burden of database configuration on the customer.

The players

UpGuard

A cybersecurity company that specializes in monitoring digital footprints and identifying data exposures in cloud environments.

Supabase

An open-source Firebase alternative that provides backend-as-a-service tools, including managed PostgreSQL databases.

The details

The exposures occurred primarily due to user misconfigurations or oversights when deploying applications. Developers often utilize AI-generated code that may contain security flaws or require specific configuration settings that users are not equipped to manage. This creates a scenario where databases, including those belonging to an Indian adult streaming site and an African government consulate in France, remained open to the public internet.

Timeline

  1. 2026: Supabase achieved a valuation of $10 billion.

  2. September 25, 2026: TechCrunch reported on the UpGuard security findings.

The Tech Race

This incident follows a recurring pattern established by the 2019 Capital One data breach, where misconfigured cloud-based infrastructure leads to the widespread exposure of sensitive user data. It underscores the challenges platforms face as they prioritize rapid deployment tools over secure-by-default configurations.

Users should monitor their accounts for suspicious activity, as exposed data included passwords and phone numbers capable of facilitating phishing attacks. Developers using platform-as-a-service tools must verify their specific database permission settings immediately.

The takeaway

The event serves as a reminder that managed cloud services do not eliminate the need for manual security configuration by the end user. Developers should audit their infrastructure settings to ensure sensitive data is not publicly accessible.

Further reading

For more information on securing cloud-hosted environments, visit the Cybersecurity section.

Live Poll

Do you trust technology platforms to secure your personal data by default?