Misconfigured Supabase deployments expose data in over 16,000 databases
Large-scale configuration errors leave personal and authentication data open, prompting urgent security reviews for Supabase-backed apps.
UpGuard reports that more than 16,000 Supabase-backed databases are exposing readable tables containing personal data, passwords, or authentication tokens due to insecure configurations. By scanning about 300,000 domains using Supabase and analyzing accessible table schemas, the firm found that over half of exposed instances leaked PII and a smaller portion also exposed credentials and tokens. Examples include a U.S. valet service leaking over 100,000 customer records, a Canadian immigration service with nearly 5,000 user entries including 884 plaintext passwords, and an adult creator platform in India exposing sensitive identity and payment information plus over 100,000 private messages. Other cases involved a Philippines OTP provider leaking 100,000 SMS messages and an African consulate exposing data on 25,000 people, all tied to issues such as missing row-level security and improper use of public keys. UpGuard links many of these issues to human operators not understanding database security settings and notes that many Supabase deployments are being created with AI-assisted tools, while recommending affected users review Supabase’s security guidance and harden their configurations.
Why it matters
This incident shows how quickly data risk can spread when managed services are adopted without a solid grasp of their security model. With thousands of databases exposing personal details, messages, and even credentials, organizations using Supabase now need to treat configuration as a primary security surface, not an afterthought, and systematically review how they protect production data.
Signal or noise?
Does this story matter, or is it hype? Decide before you see what everyone else thinks.
Sources
- BleepingComputer