More Than 16,000 Supabase Databases Exposed PII, Passwords and Authentication Tokens
Researchers have identified more than 16,000 misconfigured Supabase databases exposing readable tables containing personally identifiable information (PII), passwords or authentication tokens.
Based on an analysis of the database table schemas, researchers at cyber risk management company UpGuard believe a small portion of the exposed information included credit card data.
Supabase database exposures affect a wide range of organizations
Supabase is an open source development platform built around PostgreSQL. It provides developers with backend services for building and launching apps and websites faster.
The platform is becoming increasingly popular among developers using artificial intelligence tools to build projects. AI-assisted development accounts for more than 60% of newly created databases.
UpGuard researchers analyzed approximately 300,000 domains that showed signs of Supabase usage and checked their “Users” tables. Some queries returned database pages, while others indicated that a “users” table did not exist but that another table with a different name could be accessed.
The researchers then used the table schemas to infer the types of data exposed across the dataset. UpGuard found PII in more than half of the leaked databases, with a smaller subset containing passwords and authentication tokens.

Source: UpGuard
Exposed Supabase databases contained sensitive customer data
One notable finding involved a US valet service where more than 100,000 customer records were exposed, including contact details, license plates and visit history.
Researchers also said they found nearly 5,000 user records at Canadian immigration offices, including 884 plaintext passwords.
UpGuard said sensitive information, payment accounts and more than 100,000 private messages were discovered on an India-based adult creator platform.
A Philippines-based OTP service exposed data belonging to more than 2,000 users and 100,000 SMS messages. The messages included communications between apparently unrelated individuals.
Records belonging to 25,000 people were also revealed by African government consulates. The information included addresses and locations of emergency housing.
Misconfigured security controls caused the exposures
Researchers believe the vulnerabilities resulted from poor application security configuration, including missing or disabled row-level security policies and misuse of public keys.
UpGuard said the security issues were not limited to any particular type of business.
“Nobody who knows the type of business you’re advertising will understand the configuration of your database, so your security settings are independent of your business type,” UpGuard explains.
“The common thread is that these sites are created by AI-coding agents and humans are unaware of their composition.”
The researchers said AI-assisted app development increases the risk of misconfigurations. However, they stressed that the scans do not prove all affected sites were built using AI coding agents.
Supabase users urged to review database security settings
UpGuard said it notified application owners when further analysis identified significant risks.
Supabase users are encouraged to review the platform’s security documentation. The Supabase advisor and API security guide can help identify exposure risks and reduce them.
Join Mikko Hypponen and security leaders from the NFL, Chanel and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, correct and revalidate at machine speed.
Source: www.bleepingcomputer.com



