Misconfigured projects on developer platform Supabase are spilling personal data onto the open web at scale, according to security researchers at UpGuard, who counted roughly 16,000 affected databases.
The exposures included names, addresses, phone numbers and user passwords, plus a smaller number of authentication tokens. UpGuard told TechCrunch the datasets spanned an Indian adult streaming site’s private conversations, thousands of licence plates belonging to a US valet service, and contact details from an immigration service. One database belonged to an African consulate in France. Most sat in the United States, but the researchers described a worldwide problem.
The root cause is customer misconfiguration rather than a breach at Supabase, which lets developers store and run databases and has grown alongside the boom in AI-built apps. The company reached a $10B valuation earlier this year. Its chief information security officer, Bil Harmer, said projects are secure by default and called security a shared responsibility, adding that Supabase notifies users when it detects exposure.
UpGuard researcher Greg Pollock said the work was meant to raise awareness. The pattern is not new: exposed storage has leaked military email, visa applications and children’s records for years, and AI-assisted software development is feeding a fresh wave.