Industry News

Thousands of Supabase-Hosted Databases Found Leaking Personal Data

TechCrunch · 25 Sept 2026
Key Takeaway If your business uses AI tools or platforms like Supabase to build apps or store customer data, have someone review the database and access permissions before launch, not after.

Cybersecurity firm UpGuard has discovered roughly 16,000 databases hosted on the development platform Supabase that were exposing personal information to the open internet. The exposed data included names, addresses, phone numbers, passwords and, in fewer cases, authentication tokens.

Supabase, which lets developers quickly build and host web and app databases, has become popular partly due to the rise of AI-assisted 'vibe-coding', where developers use AI tools to generate app code quickly. However, this speed can come at a cost: AI-generated code often contains security flaws, and developers may not realise their database needs specific configuration to stay private. Similar misconfiguration issues have previously caused major leaks of military emails, visa applications, government files and personal records.

The findings point to a growing pattern: as AI tools make it easier to build and launch apps quickly, they can also make it easier to accidentally expose sensitive data if security settings aren't properly checked before going live.

data exposure Supabase AI security misconfiguration data breach
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from TechCrunch. We link back to every original so you can read it yourself.