In section Startups & Technology

Thousands of Supabase Databases Found Leaking Sensitive User Information

Security researchers at UpGuard have identified approximately 16,000 databases hosted on the Supabase platform that are publicly exposing sensitive personal information to the open web. The findings reveal a widespread pattern of misconfiguration that leaves millions of private records, including addresses and authentication tokens, vulnerable to unauthorized access.

Thousands of Supabase Databases Found Leaking Sensitive User Information

The exposed data encompasses a diverse range of sensitive materials, including private conversations from an adult streaming site, license plate logs from a valet service, and contact information linked to an immigration consultancy. UpGuard also discovered a database belonging to an African government consulate in France and another utilized by a virtual SIM farm to intercept text messages for potential phishing scams. While the majority of these instances are concentrated in the United States, the vulnerability affects projects on a global scale.

This incident underscores the risks inherent in the rise of rapid application development. As developers increasingly rely on AI-driven coding tools to build and deploy platforms, they often lack the expertise to manage complex security configurations. Bil Harmer, Chief Information Security Officer at Supabase, maintained that the platform remains secure by default. He emphasized that security is a shared responsibility, asserting that the company provides the necessary tooling while customers retain control over individual project settings. Supabase continues to implement platform updates aimed at simplifying secure deployment for its user base.

Share:on TelegramXFacebook

Subscribe to our newsletter

Once a week — the best stories from our editors, no ads or push notifications. Delivered Sunday morning.

Comments (0)

Leave a comment

No comments yet. Be the first!