UpGuard finds 16,000 misconfigured Supabase databases exposing data
UpGuard researchers found over 16,000 misconfigured Supabase databases with readable tables containing personally identifiable information, passwords, and authentication tokens. Some exposed data included credit card details, and AI-assisted development accounts for more than 60% of newly created databases.
- About 300,000 domains scanned; 16,000+ had exposed tables
- Over half of exposed databases leaked PII, some with passwords and tokens
- Victims include services in the US, Canada, India, the Philippines and Africa
- Cause: weak row-level security policies and misuse of public keys
Read next
Security