GLOBAL LIVE DESKS&P 500:7,743.41(+0.51%)FTSE 100:10,695.25(+0.14%)NIKKEI 225:66,364.20(+1.30%)BRENT CRUDE:$97.44(-2.77%)GOLD:$4,321.20(+0.54%)
RDU Global
🌐
Back to Global Desk
2026/09/27Cybersecurity & Cyber Warfare

Thousands of Supabase Databases Expose Sensitive Data as AI App Boom Fuels New Breach Wave

Cybersecurity researchers say roughly 16,000 databases hosted on Supabase have exposed personal information to the public web, underscoring how fast-growing AI app development can outpace basic security practices. The findings highlight a widening risk in vibe-coded apps, where misconfigurations and weak access controls can leave names, phone numbers, passwords and other sensitive records accessible online.

R

RDU Global Correspondent

Cybersecurity Desk

San Francisco, United States 2h ago•5 min read
🌐 Global Edition • Cybersecurity & Cyber WarfareRDU GLOBAL CORRESPONDENT
VERIFIED WIRE INTELLIGENCE

"Thousands of Supabase Databases Expose Sensitive Data as AI App Boom Fuels New Breach Wave"

Cybersecurity researchers say roughly 16,000 databases hosted on Supabase have exposed personal information to the public web, underscoring how fast-growing AI app development can outpace basic security practices. The findings highlight a widening risk in vibe-coded apps, where misconfigurations and weak access controls can leave names, phone numbers, passwords and other sensitive records accessible online.

Thousands of databases hosted on the developer platform Supabase have been found exposing sensitive personal information to the public internet, according to new research from cybersecurity firm UpGuard, in a finding that adds fresh urgency to concerns about the security of AI-built and rapidly deployed apps.

UpGuard told TechCrunch that it identified around 16,000 databases on which some degree of personal data was exposed while hosted by Supabase, a platform used by web and app developers to store and run databases. The exposed information included publicly accessible names, addresses, phone numbers and user passwords, with a smaller number of passwords and authentication tokens also found in the research.

The scale of the exposure is notable not only for the number of affected databases, but also for the range of projects tied to them. UpGuard said the exposed datasets included private conversations with sex workers on an Indian adult streaming site, thousands of license plates from a U.S. valet service, and contact information belonging to people who used an immigration and relocation service. One database belonged to an African government's consulate in France, while another was used to intercept text messages for a virtual SIM farm that sent one-time passcodes used to verify online accounts — a technique often associated with scams and phishing operations.

The findings point to a broader problem in the current wave of AI-assisted development, where so-called vibe-coded apps can be created quickly but may be deployed with serious security gaps. AI tools can make it easier than ever to build websites and apps, but the generated code can contain flaws, and developers may not understand the specific configuration steps needed to secure the databases behind them. In practice, that can mean sensitive records are left exposed through basic misconfiguration rather than sophisticated intrusion.

The issue is not new. Over the years, countless breaches have stemmed from improperly configured storage servers, databases and websites, leading to leaks of military emails, immigration and visa applications, classified government files, hundreds of thousands of driver's license scans and children's personal information. What is changing, researchers say, is the speed and scale at which such mistakes are now being made as AI tools accelerate app development and lower the barrier to launching products.

Supabase, which earlier this year reached a $10 billion valuation amid surging demand from developers building on the platform, has become a popular home for startups and independent builders. That popularity has also brought scrutiny. The company has faced criticism over how it handles user security, and there have been widely documented cases of customers misconfiguring or unknowingly exposing their databases to the broader internet, in some cases involving millions of records.

UpGuard said its research was designed to understand the scale of exposed data across the platform. While the majority of the exposed datasets appear to be located in the United States, the firm said the problem is global. The findings build on earlier research that also identified exposed databases hosted on Supabase, including those tied to Y Combinator startups and other popular apps.

Supabase has made changes to its platform over time, including bolstering its platform and user access to databases. But the latest findings suggest that even with improved tooling, the burden of secure configuration still falls heavily on developers and the companies using the service.

When reached for comment, Supabase Chief Information Security Officer Bil Harmer said the company had not seen the research, but maintained that its projects are "secure by default." He described security as a shared responsibility between Supabase and its customers. "We provide secure defaults and tooling, and customers control how their own projects are configured," Harmer said, adding that the company notifies affected customers when security issues are discovered.

"Security at Supabase is never finished. We care deeply about getting it right, and we'll keep making it easier for every developer to ship securely," Harmer said.

The episode underscores a central tension in the AI software boom: the same tools that make it easier to launch products quickly can also make it easier to ship insecure systems at scale. As more developers turn to platforms like Supabase to power vibe-coded apps, the line between rapid innovation and public exposure of private data is becoming increasingly thin.

Editorial & Verification Notice

Reported by RDU Global Correspondent. Formatted and verified using real-time institutional and journalistic wire feeds. Independent reporting adhering to the RDU Global Editorial Code of Conduct.

Related Coverage

Big Tech, Cloud & Semiconductors

Breaking the Walled Gardens: How the EU's Digital Markets Act and US DOJ Lawsuits are Forcing Tech Open

The world’s most valuable digital platforms are being pushed into a structural reset. In Brussels, the EU’s Digital Markets Act is forcing designated “gatekeepers” to open app distribution, loosen default settings, and permit greater interoperability across mobile ecosystems. In Washington, the US Department of Justice and state attorneys general are pursuing antitrust cases that challenge the economics of search, app stores, advertising, and platform self-preferencing. Together, the two regimes are attacking the same business model from different angles: control of access, defaults, and data flows. The stakes are not just legal. They reach into the trillion-dollar logic of mobile software, cloud infrastructure, and digital advertising, where Apple, Google, Amazon, and Meta have built durable tollbooths around user attention and developer dependence. Compliance is already reshaping product design, legal budgets, and revenue forecasts. But the counteroffensive is equally significant: Big Tech argues that mandated openness could weaken security, fragment user experience, and reduce incentives to invest. The result is a transatlantic contest over whether digital markets should remain vertically integrated ecosystems or be treated as regulated infrastructure.

Special Report (Sept 27, 2026)
Cybersecurity & Cyber Warfare

State-Sponsored Ransomware and Subsea Cables: The Invisible Battlefield Underpinning Global Finance

The global financial system depends on a physical layer most executives rarely see: more than 95% of intercontinental data traffic moves through subsea fiber optic cables, while a handful of clearing, cloud, and telecom chokepoints route trillions of dollars in daily transactions. That hidden architecture is now being probed by state-aligned advanced persistent threats, ransomware crews, and zero-day brokers operating in a market where a single exploit can fetch millions of dollars. The result is a new form of coercion: not just data theft, but the ability to slow payments, disrupt hospitals, and raise the cost of trust itself. In Geneva, where global banking, diplomacy, and cyber policy intersect, the strategic question is no longer whether critical infrastructure can be attacked, but how much disruption adversaries need to inflict before markets, insurers, and governments change behavior. Subsea cable sabotage remains difficult and conspicuous, yet cyber operations against landing stations, network management systems, and interbank messaging platforms can produce similar systemic anxiety at far lower cost. The battlefield is invisible, but the economic consequences are immediate: liquidity stress, operational paralysis, and a premium on resilience that many institutions still underinvest in.

Special Report (Sept 27, 2026)
Clean Energy & Climate Transition

The Small Modular Nuclear Reactor (SMR) Renaissance: Fact vs. Regulatory Reality in Clean Decarbonization

Small modular reactors have become the nuclear industry’s most persuasive answer to the intermittency problem in a decarbonizing grid: factory-built, supposedly cheaper, and easier to deploy than gigawatt-scale plants. But the commercial narrative is running ahead of the regulatory and fuel realities. Across the leading Western designs—NuScale, Westinghouse and Rolls-Royce SMR—licensing timelines remain long, first-of-a-kind costs remain unproven, and the supply chain for HALEU fuel is still too thin to support a rapid buildout. The result is a widening gap between policy ambition and industrial capacity. Governments want firm, low-carbon power; utilities want bankable economics; regulators want safety cases that survive scrutiny; and investors want projects that do not repeat the cost overruns of past nuclear waves. In Vienna, where energy security and climate policy are increasingly inseparable, the SMR question is no longer whether the technology can work in principle, but whether it can be deployed at scale before the decarbonization window narrows further.

Special Report (Sept 27, 2026)