Researchers at cyber risk management company UpGuard found more than 16,000 misconfigured Supabase databases with readable tables containing personal information, passwords or authentication tokens. Based on table schemas, they believe a very small portion of the exposed information includes credit card data.
Supabase is an open-source development platform built around PostgreSQL. UpGuard analyzed about 300,000 domains that appeared to use Supabase and checked their databases for a “users” table. When that table was not found, some queries indicated that another table could still be accessed. Researchers used table schemas to infer the types of data exposed.
More than half of the exposed databases contained personally identifiable information, while a smaller subset included passwords and authentication tokens. Examples included a U.S. valet service with more than 100,000 customer records, a Canadian immigration service with nearly 5,000 user records—including 884 plaintext passwords—and a Philippines-based OTP service exposing data on more than 2,000 users and 100,000 SMS messages.
UpGuard also reported exposed records for 25,000 people at an African government consulate. The researchers linked the exposures to weak application security configurations, including missing or ineffective row-level security policies and misuse of public keys. They said AI coding agents may be a common factor in some cases, but their scans did not establish that every affected site was built with one. UpGuard said it notified application owners when deeper analysis found significant exposure.
Comments
0No comments yet. Be the first to comment.