Core Event
Cybersecurity firm UpGuard released research on September 25, 2026, revealing that thousands of databases hosted on the development platform Supabase are publicly exposing users’ sensitive information. The platform, which has surged in popularity alongside AI-coded and low-code (vibe-coded) applications, faces widespread security misconfiguration issues.
- Approximately 16,000 Supabase-hosted databases exhibited some degree of personal data exposure
- Exposed data types include names, addresses, phone numbers, user passwords, and authentication tokens
- Leaked databases span various business scenarios: adult streaming platforms, license plate management services, immigration/relocation services, consular systems, and virtual SIM farms
- Most affected databases are U.S.-based, though UpGuard stresses this is a global issue
Details and Counterintuitive Findings
UpGuard’s research uncovered specific cases with high sensitivity:
- An Indian adult streaming site retained private chat logs between sex workers and clients;
- A U.S. valet service database contained license plate records for thousands of vehicles;
- An immigration and relocation service database exposed user contact details;
- One database belonged to an African consulate in France;
- Another was part of a virtual SIM farm used to intercept SMS one-time passcodes, typically deployed in phishing and scam operations.
The key counterintuitive finding: Supabase, which achieved a $10 billion valuation earlier this year as a developer-friendly platform, simultaneously hosts multiple cases where users have erroneously or unknowingly exposed their databases to the public internet, with some incidents involving millions of records per case.
The platform enables developers to store and run databases, but its security model rests on “secure by default” principles while emphasizing shared responsibility with customers.
Platform Response and Responsibility
Supabase’s Chief Information Security Officer Bil Harmer responded that the company’s projects are “secure by default,” and security is a shared responsibility between the company and its customers:
- Supabase provides secure defaults and tooling;
- Customers control their project configurations;
- The company notifies affected customers upon discovering security issues.
Harmer stated: “Security at Supabase is never finished. We care deeply about getting it right, and we’ll keep making it easier for every developer to ship securely.”
UpGuard security researcher Greg Pollock emphasized such research is crucial for raising awareness about data exposure issues.
Platform History and Security Evolution
Technical background: Supabase is an open-source BaaS (Backend-as-a-Service) platform built on PostgreSQL, offering database, authentication, storage, and real-time subscriptions. Its goal is to lower full-stack development barriers, especially for developers using AI coding or low-code (vibe-coding) to generate applications.
BaaS (Backend-as-a-Service) is a cloud computing model that accelerates development by providing ready-to-use backend functionality, eliminating the need for developers to deploy servers independently. However, such platforms’ security heavily depends on developers understanding default configurations and actively hardening them.
Historically, misconfigured storage systems have caused numerous breaches involving autonomous vehicle data, government agencies, healthcare information, and even military emails. This study is another instance of such incidents, highlighting how the rapid adoption of low-code/no-code tools often outpaces developers’ awareness of configuration risks.
📋 Data Exposure Types
| Exposure Type | Description | Risk Level |
|---|---|---|
| Identity Data | Names, addresses, phone numbers | High |
| Authentication Data | User passwords, authentication tokens | Critical |
| Behavioral Data | Private chat logs, passcode interception logs | Critical |
| Credential Data | License plates, visa applications, passport scans | High |
##落地 Recommendations
Audiences who should act immediately:
- Developers already using Supabase or similar BaaS platforms: Immediately review database network access policies, disabling public read/write permissions, especially for fields containing personal user data.
- Startups using low-code/AI-generated code tools: Ensure proper row-level security (RLS) is configured rather than relying on permissive default permissions.
Situations where delaying deployment is advisable:
- New projects involving highly sensitive data (biometrics, government IDs, financial information): Conduct third-party security audits or at minimum perform comprehensive configuration reviews before production deployment; “secure by default” does not mean “configure and forget”.
Written at the End
The Supabase case reaffirms that usability and security often exist in tension. As development barriers lower, security education and configuration risk awareness must advance in parallel—otherwise, even the most “secure by default” platforms cannot prevent mass data breaches caused by human error.
