Skip to content

Supabase misconfigurations expose thousands of databases to the web

Cybersecurity firm UpGuard has identified approximately 16,000 databases hosted on Supabase that were exposing sensitive data to the public internet due to misconfigurations. The findings, reported by TechCrunch, include cases involving government and private sector projects worldwide, raising concerns about security practices on developer-focused platforms.

By

Editor, LazyFounders

Published 5 min read
Supabase misconfigurations expose thousands of databases to the web
Image: Image Credits:Thomas Fuller / SOPA Images / LightRocket / Getty Images via source

Cybersecurity firm UpGuard has identified approximately 16,000 databases hosted on Supabase that were exposing sensitive data to the public internet due to misconfigurations. The findings, reported by TechCrunch, include cases involving government and private sector projects worldwide, raising concerns about security practices on developer-focused platforms.

30 SEC SUMMARY

  • Cybersecurity firm UpGuard identified around 16,000 Supabase-hosted databases exposing sensitive data due to misconfigurations.
  • Exposed data includes personal details, passwords, and government/private sector information.
  • Supabase’s CISO states security is a shared responsibility between the platform and its users.
  • Cases include an African government consulate and a U.S. valet service with exposed databases.
  • Supabase, valued at $10 billion in 2026, faces scrutiny over its handling of security configurations.

TABLE OF CONTENTS

  • Thousands of Supabase databases expose sensitive data
  • Global cases highlight extent of exposure
  • Shared responsibility model under scrutiny
  • Background: Cloud security challenges persist
  • Developing: what is not yet confirmed
  • What this means
  • Key takeaways
  • FAQ
  • Sources

KEY HIGHLIGHTS

  • Around 16,000 Supabase-hosted databases were found exposing personal data due to misconfigurations.
  • Exposed data includes names, passwords, and sensitive information from government and private sector projects.
  • Supabase’s CISO emphasizes that security is a shared responsibility between the platform and its users.
  • UpGuard’s research reveals global cases, including an African government consulate and a U.S. valet service.
  • Supabase, valued at $10 billion in 2026, faces criticism for its handling of user security configurations.

Thousands of Supabase databases expose sensitive data

Cybersecurity firm UpGuard has reported that approximately 16,000 databases hosted on Supabase, a popular open-source alternative to Firebase, were exposing sensitive data to the public internet. According to TechCrunch, the exposed data includes personal information such as names, addresses, phone numbers, passwords, and confidential records linked to government and private sector projects worldwide.

The findings underscore persistent risks associated with misconfigured cloud databases. Supabase, which achieved a $10 billion valuation earlier in 2026, has faced criticism for its approach to user security, particularly regarding widely documented cases of misconfigurations or accidental exposures.

Global cases highlight extent of exposure

UpGuard’s research uncovered several high-profile cases of data exposure. Among them was a database linked to an African government’s consulate in France, as well as one used by a U.S. valet service to manage customer data. Another case involved a database intercepting text messages via a virtual SIM farm, potentially exposing one-time passcodes and other sensitive communications.

These incidents reflect broader trends in cloud security, where rapid adoption and ease of deployment often outpace security best practices. The exposed databases were reportedly accessible due to default or improper security settings, rather than vulnerabilities in Supabase’s infrastructure.

Shared responsibility model under scrutiny

Bil Harmer, Supabase’s Chief Information Security Officer, stated that security is a shared responsibility between the platform and its users. While Supabase notifies affected customers when security issues are detected, users remain responsible for configuring their databases securely.

This model aligns with approaches taken by other cloud providers like AWS and Google Cloud. However, critics argue that default settings should prioritize security over convenience, especially as AI-generated code accelerates deployment without always improving security hygiene.

Background: Cloud security challenges persist

Misconfigured databases have long been a leading cause of data breaches, affecting companies across industries. Supabase, backed by Y Combinator, has gained traction for its developer-friendly tools, which simplify database management and deployment. However, its rapid growth has drawn attention to the security implications of its open-source model and default settings.

Similar challenges have affected other cloud platforms, including AWS, MongoDB, and Firebase. These cases highlight the need for better education and tooling to help developers secure their deployments effectively.

Developing: what is not yet confirmed

The following is reported but has not been independently confirmed.

The reported number of exposed databases—approximately 16,000—and Supabase’s $10 billion valuation have not been independently verified. Additionally, specifics about the African government consulate and U.S. valet service cases are based on UpGuard’s research and have not been confirmed by the affected organizations.

What this means

LazyFounders analysis — our interpretation, not reported fact.

This situation highlights a recurring challenge for developer-focused cloud platforms: balancing ease of use with robust security defaults. For founders and operators, the lesson is clear—assuming default settings are secure is a risky bet, particularly when handling sensitive or regulated data. Supabase’s rapid growth and $10 billion valuation reflect its popularity, but its misconfiguration issues echo problems faced by AWS, MongoDB, and others. The rise of AI-generated code could worsen this trend, as developers deploy databases at scale without always prioritizing security. Supabase’s response will be critical in determining whether it can address these gaps without sacrificing the simplicity that made it attractive to developers.

Key takeaways

  • Misconfigured databases remain a leading cause of unintended data exposure in cloud platforms.
  • Supabase’s $10 billion valuation underscores its popularity but also intensifies scrutiny of its security practices.
  • Shared responsibility models require users to actively manage security settings—defaults are rarely sufficient.
  • AI-generated code may increase misconfiguration risks if developers lack security expertise.

FAQ

What caused the exposure of these Supabase databases?

The exposures were primarily due to misconfigurations or improper security settings applied by users. Default settings may not prioritize security, leaving databases accessible to the public internet.

How does Supabase handle security responsibilities?

Supabase operates under a shared responsibility model, where the platform provides security tools and notifications, but users are responsible for configuring their databases securely.

Are other cloud platforms facing similar issues?

Yes. Misconfigured databases are a common cause of data breaches across cloud platforms, including AWS, MongoDB, and Firebase. Rapid adoption of cloud tools often outpaces security best practices, leading to unintended exposures.

What risks does AI-generated code pose to database security?

AI-generated code can accelerate deployment but may lack security considerations, particularly if developers lack expertise in secure configuration. This could increase the likelihood of misconfigurations and unintended data exposures.

Related on LazyFounders

Sources

  1. TechCrunch · 2026-09-25
    Some Supabase customers are publicly exposing reams of people’s data to the web

This story is an original summary drafted with AI by LazyFounders from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are LazyFounders's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.

Get the LazyFounder Brief

Startup, funding and AI news in a five-minute read. Join the early-access list.

Lazy Founder - Powered by Blogy.in