UpGuard identified 16,326 Supabase-hosted databases with publicly accessible tables, revealing a broad customer-side cloud-configuration failure. About half reportedly exposed personally identifiable information; exposed records also included private conversations, U.S. license-plate data, immigration and relocation-service contacts, passwords, authentication tokens, and in rare cases payment-card information. One database was allegedly associated with a virtual SIM farm linked to an African government consulate in France.
The researchers attributed the exposures to misconfigured access controls rather than a vulnerability in Supabase itself, warning that rapid deployment aided by AI coding tools can compound configuration risk. Supabase said projects are secure by default but that database permissions remain a shared responsibility, underscoring the need for customers to audit public tables, enforce least-privilege access controls, and rotate any credentials or tokens exposed through affected databases.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
Supabase said projects are secure by default and that database security configuration is shared with customers. Its information-security leadership said customers control project configurations while Supabase provides secure defaults, tools, and threat notifications.
UpGuard identified 16,326 Supabase-hosted databases with publicly accessible tables, finding that roughly half exposed personally identifiable information and some exposed passwords, authentication tokens, or payment-card data. The firm attributed the issue to customer-side database access-control misconfigurations rather than an inherent Supabase platform breach.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.