Trusence Technology, daily
Last updated 26 September 2026 Türkçe
← All stories
Security

Misconfigured Supabase apps left personal data on about 16,000 databases exposed

The leak highlights how small security mistakes in app setup can leave personal data openly accessible.

UpGuard found that around 16,000 databases hosted on Supabase had at least some personal information accessible to the public, a concern for teams using the platform to store app data. The exposed material included names, addresses, phone numbers and user passwords; the researchers found fewer passwords and authentication tokens. UpGuard said the findings illustrate how basic setup mistakes in AI-built apps can expose sensitive records. Most of the affected datasets appeared to be in the United States, but UpGuard said the issue is global. Supabase said it provides secure defaults and tools, while customers configure their projects, and that it notifies affected customers when it finds security issues.

Why it matters

For teams building on Supabase, this shows how configuration choices directly affect user privacy. Personal details like names, addresses, phone numbers and even some passwords were left publicly reachable, with most exposed datasets in the United States but impact stretching worldwide. The incident underlines that secure defaults are not enough on their own, and that developers must actively harden access and review settings, even when using managed database platforms.

Sources

  • TechCrunch