A new security investigation has uncovered a large number of publicly accessible databases hosted on Supabase, potentially exposing sensitive information belonging to people around the world.
Cybersecurity company UpGuard said its research identified approximately 16,000 Supabase databases containing some form of personal information that could be accessed from the public internet.
Supabase is a popular development platform that allows developers to build applications and store their databases without having to manage the underlying infrastructure themselves. Its popularity has grown rapidly as more developers use AI-powered coding tools to create websites and applications.
The latest findings, however, highlight a security challenge that can arise when developers configure these systems incorrectly.
Personal information found in exposed databases
According to UpGuard, researchers discovered publicly accessible records containing names, addresses, telephone numbers and passwords. A smaller number of databases also exposed authentication tokens and other credentials.
The exposed information was not limited to a particular type of application.
Researchers found databases containing private conversations from an Indian adult streaming service, thousands of vehicle license plates belonging to a U.S. valet company and contact information associated with an immigration and relocation service.
In one case, UpGuard identified a database connected to an African government consulate in France.
Another exposed database was associated with a virtual SIM operation used to receive text messages containing one-time verification codes. Such services can potentially be abused for account takeovers, scams and phishing campaigns.
While many of the exposed databases were located in the United States, UpGuard said the problem extends well beyond the country.
AI-powered development adds another security challenge
The findings also highlight a growing concern surrounding so-called AI-assisted or “vibe-coded” applications.
Modern AI coding tools allow people with limited programming experience to build functioning websites and applications relatively quickly. However, generating an application is only part of the process. Developers still need to correctly configure databases, authentication systems and access controls.
A poorly configured database can therefore leave sensitive information exposed even when the application itself appears to work normally.
Similar configuration mistakes have previously resulted in major leaks involving government information, immigration records, identification documents and other sensitive data.
With more developers turning to AI tools to build applications, security researchers are increasingly concerned that these mistakes could occur at a much larger scale.
Supabase says security is a shared responsibility
Supabase has introduced several security improvements over the years, including additional controls around database access and project configuration.
The company’s Chief Information Security Officer, Bil Harmer, said Supabase had not reviewed the specific research when contacted, but maintained that projects are secure by default.
Harmer emphasized that security is shared between Supabase and its customers. The platform provides security tools and default protections, while developers remain responsible for how they configure their individual projects.
He also said the company works to notify customers when security problems are identified.
A growing problem for modern developers
The research illustrates a broader issue facing today’s software industry: making application development easier does not automatically make applications secure.
As AI makes it possible to build software faster, developers still need to understand permissions, authentication, database policies and other security controls.
For organizations handling personal or confidential information, a simple configuration mistake can potentially expose thousands or even millions of records.
UpGuard researcher Greg Pollock said the company’s investigation is intended to raise awareness about the risks of publicly accessible databases and encourage developers to take greater care when deploying applications.
The findings serve as another reminder that convenience and rapid development need to be balanced with proper security practices—particularly as AI-driven development continues to expand.
