{
  "id": 9796243,
  "title": "Some Supabase customers are publicly exposing reams of people’s data to the web",
  "url": "https://urgent.news/2026/09/25/some-supabase-customers-are-publicly-exposing-reams-of-peoples-data",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-25T17:29:46.000Z",
  "source": {
    "name": "TechCrunch",
    "slug": "techcrunch",
    "url": "https://techcrunch.com/2026/09/25/some-supabase-customers-are-publicly-exposing-reams-of-peoples-data-to-the-web/"
  },
  "original_language": "en",
  "account": "A recent security investigation by cybersecurity firm UpGuard has revealed that thousands of databases hosted by the popular development platform Supabase are inadvertently exposing sensitive personal data to the public web. Supabase, which enables web and app developers to store and run their databases, recently reached a $10 billion valuation due to the increasing number of developers utilizing the platform for their vibe-coded apps. However, the company has faced criticism over its handling of user security, with documented instances of users unintentionally exposing vast amounts of data.\n\nThe UpGuard research uncovered approximately 16,000 databases with some level of personal data exposed while hosted by Supabase. The exposed information includes names, addresses, phone numbers, and user passwords, revealing data linked to various projects such as private conversations involving sex workers, license plates from a U.S. valet service, and contact information from an immigration and relocation service. One database belonged to an African consulate in France, while another was used to intercept text messages through a virtual SIM farm, which could be used to launch scams and phishing attacks.\n\nAlthough the exposed datasets appear to primarily be located in the United States, UpGuard emphasizes that this is a global issue. The findings build upon earlier research that identified a range of exposed databases hosted on Supabase, including those belonging to Y Combinator startups and other popular applications. Supabase's Chief Information Security Officer, Bil Harmer, stated that the company's projects are \"secure by default\" and that security is a shared responsibility between the company and its customers. Harmer highlighted that customers have control over how their projects are configured, and the company notifies affected customers when security issues are identified. He emphasized that Supabase's commitment to security is ongoing, as the company strives to make it easier for developers to ship software securely.",
  "summary": "The findings highlight how AI-generated and vibe-coded apps can spill and expose users' data when not configured or secured properly.",
  "key_points": [
    "Approximately 16,000 Supabase databases exposed personal data",
    "Exposed information includes names, addresses, phone numbers, passwords",
    "Supabase emphasizes security is shared responsibility between company and customers"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}