$ 44.77 € 50.99 zł 11.66
+9° Kyiv +12° Warsaw +17° Washington

About 16,000 databases with exposed personal data found on Supabase — TechCrunch

Lev Shevtsov 25 September 2026 20:33
About 16,000 databases with exposed personal data found on Supabase — TechCrunch

Researchers from cybersecurity company UpGuard have discovered about 16,000 databases hosted on the developer platform Supabase in which personal data was accessible on the open internet. TechCrunch reports.

Supabase allows developers to store data and work with databases for websites and applications. According to UpGuard, publicly accessible information included names, addresses, phone numbers, user passwords, and authentication tokens.

What data the researchers found

UpGuard said that the accessible databases contained data from various projects. In particular, researchers found private conversations with female sex workers on an Indian adult website, thousands of vehicle license plate numbers from a parking service in the United States, and contact information of people who used an immigration and relocation service.

According to the company, one of the databases belonged to the consulate of an African state in France. Another was used by a virtual SIM farm to intercept text messages containing one-time codes intended to verify online accounts. UpGuard noted that such SIM farms are typically used to launch fraud and phishing attacks.

More current news is available on the UA.News Telegram channel Telegram.

Risks of misconfiguration

Most of the identified datasets are located in the United States, according to UpGuard, but the issue is global in nature. The study's findings indicate that applications and websites created using artificial intelligence tools may expose sensitive data because of basic configuration errors or inadequate protection. TechCrunch also noted that researchers had previously found other open databases on Supabase, including ones linked to Y Combinator startups and popular applications.

Supabase Chief Information Security Officer Bill Harmer said the company had not yet reviewed UpGuard's research. He stressed that the platform's projects are secure by default and that security is a shared responsibility between the service and its customers. According to him, Supabase provides secure default settings and tools, while customers determine the configuration of their own projects; the company also notifies customers about identified security issues.

UpGuard researcher Greg Pollock said the company's goal was to draw attention to the issue of public data exposure.

Read us on
Download our app