Supabase databases found leaking personal data from misconfigured apps

Security researchers at UpGuard found roughly 16,000 Supabase-hosted databases exposing personal information to the public internet. The exposed data included names, addresses, phone numbers, passwords, and records from projects such as a valet service and an immigration service. The report links the problem to misconfigured apps, including those built with AI-assisted or vibe-coding tools.
UpGuard's review identified about 16,000 Supabase-hosted databases with some personal data publicly reachable. Exposed fields included names, addresses, phone numbers, passwords, and a smaller set of authentication tokens. The affected projects ranged from an Indian adult streaming service's private chats to a U.S. valet operator's license plates and an immigration/relocation service's contacts.
Other examples included an African consulate in France and a virtual SIM operation that intercepted texts for one-time passcodes, often tied to scams. Most exposed datasets appeared U.S.-based, though UpGuard called it global. Supabase's CISO said projects are secure by default and security is shared; UpGuard researcher Greg Pollock said the work raises awareness.
People whose records appeared in these databases—including users of adult, valet, immigration, and consular services—could face scams, identity theft, or unwanted contact. Developers and small teams relying on AI-assisted tools may not realize misconfigurations expose users, potentially damaging trust and inviting regulatory scrutiny. Supabase and similar platforms may face pressure to strengthen defaults and onboarding, while users may become more cautious about where they submit personal data. The broader vibe-coding boom could amplify these risks if security education does not keep pace.