UpGuard says about 16,000 Supabase databases exposed personal data
UpGuard says it found about 16,000 databases hosted by Supabase with some personal data publicly accessible. The case highlights the risks of misconfigured applications built with artificial intelligence tools.
Why it matters · editorial interpretation
The case may caution teams using AI-generated code not to treat security configurations as an operational detail. UpGuard said the exposure affected personal data in about 16,000 databases; Supabase says projects are secure by default and configuration is a shared responsibility with customers.
Cybersecurity firm UpGuard found about 16,000 databases hosted by Supabase that exposed some personal data, the company told TechCrunch. The publicly accessible information included names, addresses, phone numbers, passwords and some authentication tokens; the data covered private conversations, vehicle license plates and contacts from immigration services. UpGuard also identified a database linked to an African government consulate in France and another used to intercept text messages from a virtual SIM operation. Most of the datasets appeared to be in the United States, but the firm said the problem is worldwide.
The episode highlights risks in applications built with artificial intelligence, whose generated code can contain flaws or require configurations developers do not understand. Supabase Chief Information Security Officer Bil Harmer told TechCrunch that projects are secure by default and that security is a shared responsibility with customers, who control their projects’ configuration.
Sources: TechCrunch