Zack Whittaker’s TechCrunch piece (published September 25, 2026, ~10:29 AM PDT) cites UpGuard’s survey of publicly accessible Supabase-hosted projects. Examples UpGuard described to TechCrunch include license plates from a U.S. valet service, contact data from an immigration/relocation service, an African government’s consulate database in France, private conversation data from an Indian adult streaming site, and a virtual SIM farm used to intercept one-time passcodes. Majority of exposed datasets appeared U.S.-located; UpGuard called it a worldwide problem. Aggregate record counts across all 16,000 databases remain Undisclosed.
Supabase CISO Bil Harmer told TechCrunch the company had not seen the research when asked, that projects are “secure by default,” and that security is a shared responsibility — Supabase provides defaults and tooling; customers control project configuration. He said the company notifies affected customers when security issues are discovered. No CVE, platform-wide exploit, or total PII record count is published in the TechCrunch report.
Why the desk cares: Supabase is a high-visibility developer backend (TechCrunch notes a $10 billion valuation earlier this year). A four-digit count of customer databases left open is Breaking for app-sec and AI-coded product risk even when the vendor’s core control plane is not the blast radius. The UpGuard attribution is per TechCrunch until UpGuard publishes its own primary write-up.
