< Back to all clusters
[TECHNOLOGY] · United States, India, France · 3 sources

started · updated

Supabase databases expose sensitive user data to the web

Research from cybersecurity firm UpGuard has revealed that approximately 16,000 databases hosted on the development platform Supabase have exposed sensitive personal information to the public internet.

The exposed data includes names, addresses, phone numbers, and user passwords. While authentication tokens and passwords were found in lower quantities than other personal identifiers, the scope of the exposure is significant. Specific instances identified include private conversations from an Indian adult media platform, vehicle license plates from a US valet service, and contact information for individuals using immigration and moving services.

One database was reportedly linked to an African nation's consulate in France, and another was connected to a virtual SIM infrastructure used for capturing one-time codes. Experts suggest the rise of AI-driven “vibe-coding”—where developers use AI tools to rapidly build applications—is contributing to these vulnerabilities. Such rapid development can lead to security flaws in generated code or improper database configurations by developers who may lack deep security expertise.

Entities

Supabase · UpGuard