EXPOSURE RESEARCH

UpGuard: ~16,000 Supabase-hosted databases exposing personal data.

UpGuard told TechCrunch it found around 16,000 databases hosted on Supabase where some degree of personal data was publicly reachable — names, addresses, and phone numbers among the finds, with a smaller set of passwords and authentication tokens. This is not a report that Supabase’s own platform was breached; the pattern is customer misconfiguration and insecure app setups, including vibe-coded stacks.

Sep 25, 2026 · 3 min read

Zack Whittaker’s TechCrunch piece (published September 25, 2026, ~10:29 AM PDT) cites UpGuard’s survey of publicly accessible Supabase-hosted projects. Examples UpGuard described to TechCrunch include license plates from a U.S. valet service, contact data from an immigration/relocation service, an African government’s consulate database in France, private conversation data from an Indian adult streaming site, and a virtual SIM farm used to intercept one-time passcodes. Majority of exposed datasets appeared U.S.-located; UpGuard called it a worldwide problem. Aggregate record counts across all 16,000 databases remain Undisclosed.

Supabase CISO Bil Harmer told TechCrunch the company had not seen the research when asked, that projects are “secure by default,” and that security is a shared responsibility — Supabase provides defaults and tooling; customers control project configuration. He said the company notifies affected customers when security issues are discovered. No CVE, platform-wide exploit, or total PII record count is published in the TechCrunch report.

Why the desk cares: Supabase is a high-visibility developer backend (TechCrunch notes a $10 billion valuation earlier this year). A four-digit count of customer databases left open is Breaking for app-sec and AI-coded product risk even when the vendor’s core control plane is not the blast radius. The UpGuard attribution is per TechCrunch until UpGuard publishes its own primary write-up.

Sources