Supabase Data Exposures Reveal the High Stakes of Cloud Security

Thousands of databases hosted by Supabase exposed sensitive personal information to the public web, turning configuration mistakes into a sweeping privacy problem. UpGuard found around 16,000 databases where some degree of personal data was accessible, revealing how a single setting can place huge collections of records beyond their intended audience.
The discovery lands at a major moment for Supabase, which reached a $10 billion valuation earlier this year. The company has built its platform around hosted databases and developer tools, but the findings show that secure infrastructure still depends on how customers configure their projects.
A Vast Collection of Exposed Personal Data
The exposed information included names, addresses, phone numbers, and user passwords. These were not isolated records from one type of service; the databases were linked to projects with very different purposes and users.
One database contained private conversations with sex workers on an Indian adult streaming site. Another held thousands of license plates connected to a U.S. valet service, while a separate database contained contact information belonging to people who used an immigration and relocation service.
One exposed database belonged to an African government’s consulate in France. Another was used by a virtual SIM farm to intercept text messages containing one-time passcodes for verifying online accounts, a system often connected to scams and phishing.
Most of the exposed datasets appear to be located in the United States, but the problem reaches around the world. The range of information shows why database exposure carries such high stakes: one misconfigured project can reveal ordinary contact details, private conversations, credentials, or data tied to government operations.
Configuration Mistakes Can Scale Into Millions of Records
Users have widely documented cases of misconfiguring databases or unknowingly exposing them to the broader internet. In some cases, those mistakes involved millions of records, turning an individual configuration error into a major data exposure.
The Supabase findings bring that pattern into focus across a large hosted platform. Around 16,000 databases had some degree of personal data exposed, and each project could carry its own combination of users, systems, and sensitive records.
That scale matters because cloud databases can collect information from many parts of a service. A project might store customer contacts, account verification messages, license plates, or private conversations in one place. When access controls do not match the intended audience, the database can expose far more than its owner expected.
UpGuard security researcher Greg Pollock said the company’s research was important for raising awareness about data exposures. That focus puts attention on the gap between creating a database and securing it for real-world use, where settings, permissions, and access controls shape who can see the information inside.
Supabase Points to Shared Security Responsibility
Supabase has made changes to its platform over the years, including bolstering its platform and user access to databases. The company’s response places secure defaults and customer configuration at the center of the issue.
Bil Harmer, Supabase’s Chief Information Security Officer, said the company’s projects are “secure by default” and that security is a shared responsibility between Supabase and its customers. He stated, “We provide secure defaults and tooling, and customers control how their own projects are configured.”
That division of responsibility creates a difficult challenge for every hosted database provider. The platform must offer strong protections and clear tools, while customers must configure their projects in ways that match the sensitivity of their data. The exposed databases show what can happen when that connection breaks.
Harmer also said, “Security at Supabase is never finished. We care deeply about getting it right, and we’ll keep making it easier for every developer to ship securely.” The statement points to an ongoing process rather than a single fix, especially as hosted databases support more projects and hold more personal information.
Supabase now faces a security story that reaches beyond one platform setting. The findings connect cloud growth, developer freedom, and privacy risk in one sharp picture: tools can make it easier to build, but the choices surrounding access can determine whether sensitive data stays protected.
With 16,000 databases linked to exposed personal data, the warning is impossible to miss. Secure defaults, stronger access controls, and clearer configuration tools will shape whether the next generation of cloud projects protects the information it collects—or places it in reach of the public web.
Based on



