Over 16,000 Supabase Databases Expose PII, Passwords, and Auth Tokens
A recent discovery by researchers at **UpGuard** has revealed more than 16,000 misconfigured **Supabase** databases, exposing sensitive data including personally identifiable information (PII), passwords, and authentication tokens. This widespread exposure highlights critical application security misconfigurations, particularly in the context of rapidly evolving AI-assisted development.
Cyber risk management firm **UpGuard** has unearthed a significant security vulnerability affecting over 16,000 **Supabase** databases. These misconfigurations have led to the exposure of readable tables containing sensitive data, including PII, passwords, and authentication tokens.
**Supabase** is an open-source development platform built around **PostgreSQL**, offering developers a suite of backend services for accelerated app and website creation. Its popularity has surged, especially among developers leveraging AI tools, with over 60% of new databases now being AI-assisted.
### The Scope of the Exposure
**UpGuard** researchers analyzed a dataset of approximately 300,000 domains indicative of **Supabase** usage. Their investigation focused on identifying accessible 'users' tables or similarly named tables containing sensitive information. The analysis of table schemas allowed them to infer the types of data exposed across the identified databases.
More than half of the exposed databases contained PII, while a substantial subset also included passwords and authentication tokens. A smaller, but still concerning, portion of the exposed information is believed to include credit card data.

*Source: UpGuard*
### Real-World Impact
The findings illustrate the severe real-world implications of these misconfigurations:
* A U.S. valet service exposed over 100,000 customer records, including contact details, license plates, and visit histories.
* A Canadian immigration service revealed nearly 5,000 user records, with 884 of those containing plaintext passwords.
* An India-based adult creator platform exposed sensitive identity and payment account details, alongside more than 100,000 private messages.
* A Philippines-based OTP service disclosed data on over 2,000 users and 100,000 SMS messages, including some personal communications.
* An African government consulate exposed records for 25,000 individuals, detailing addresses and emergency housing locations.
### Root Causes and Mitigation
**UpGuard** attributes these exposures primarily to poor application security configurations. This includes the absence or ineffectiveness of row-level security policies and the misuse of public keys.
The researchers emphasize that the issue transcends specific business types, stating, βThe common thread is that these sites are created by AI coding agents and the humans are unaware of the configuration.β While AI-assisted development is highlighted as increasing the risk of misconfigurations, the researchers clarified that their scans do not definitively link every affected site to AI coding agents.
**UpGuard** has initiated notifications to application owners where significant exposure was identified through deeper analysis.
**Supabase** users are strongly advised to review the platformβs security documentation, including its [advisors](http://supabase.com/docs/guides/observability/advisors) and [API security guide](https://supabase.com/docs/guides/api/securing-your-api), to proactively identify and mitigate potential exposure risks.