<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/some-supabase-customers-are-publicly-exposing-reams-of-people-s-data-to-the-web-ftusoweiz" -->

---
title: Some Supabase customers are publicly exposing reams of...
description: Security firm UpGuard found roughly 16,000 Supabase-hosted databases publicly exposing personal data, including names, addresses, phone numbers, and passwords,...
canonical: https://daily.dev/posts/some-supabase-customers-are-publicly-exposing-reams-of-people-s-data-to-the-web-ftusoweiz
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Some Supabase customers are publicly exposing reams of people’s data to the web | daily.dev
og:description: Security firm UpGuard found roughly 16,000 Supabase-hosted databases publicly exposing personal data, including names, addresses, phone numbers, and passwords,...
og:url: https://daily.dev/posts/some-supabase-customers-are-publicly-exposing-reams-of-people-s-data-to-the-web-ftusoweiz
og:image: https://api.daily.dev/og/posts/fTusoWeiz.png
og:image:alt: Some Supabase customers are publicly exposing reams of people’s data to the web
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Some Supabase customers are publicly exposing reams of people’s data to the web

**[TechCrunch](https://daily.dev/sources/tc)** · 3 min read · 0 upvotes · 0 comments

## Summary

Security firm UpGuard found roughly 16,000 Supabase-hosted databases publicly exposing personal data, including names, addresses, phone numbers, and passwords, due to misconfigurations often tied to AI-generated or vibe-coded apps. Exposed datasets came from wildly varied projects, from an adult streaming site's private conversations to a foreign consulate's records and a SIM farm used for scam verification codes. Supabase, valued at $10 billion after a surge in vibe-coding adoption, says security is a shared responsibility and its defaults are secure, while critics point to a pattern of prior exposures tied to the platform.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://techcrunch.com/2026/09/25/some-supabase-customers-are-publicly-exposing-reams-of-peoples-data-to-the-web>

## Questions this post answers

### Why are so many Supabase databases leaking personal data publicly?

Security research from UpGuard found around 16,000 Supabase-hosted databases exposing personal data such as names, addresses, phone numbers, and passwords, largely due to misconfigured access controls rather than a platform vulnerability. Many of these apps were vibe-coded using AI tools, which can generate code with security flaws or require configuration steps developers are unaware of, leaving row-level security or API access improperly locked down.

_Anyone shipping a vibe-coded app on supabase can use daily.dev to stay ahead of similar data-exposure lessons._

### Is Supabase secure by default for storing user data?

Supabase's Chief Information Security Officer Bil Harmer states that projects are secure by default, describing security as a shared responsibility where Supabase provides secure defaults and tooling while customers control their own project configuration. Despite this, independent research has repeatedly found large-scale data exposures across Supabase-hosted projects, including cases affecting Y Combinator startups and other popular apps.

_Developers weighing backend platforms for sensitive data can track supabase security debates on daily.dev._

## Similar posts on daily.dev

- [AI-built app on Lovable exposed 18K users, researcher claims](https://daily.dev/posts/ai-built-app-on-lovable-exposed-18k-users-researcher-claims-wdpsjqwku) · The Register · 0 upvotes · 0 comments
- [Supaguard : Scan, Detect & Protect Your Supabase Data](https://daily.dev/posts/supaguard-scan-detect-protect-your-supabase-data-6gz35nc3a) · Product Hunt · 0 upvotes · 0 comments

---

Tags: [#vibe-coding](https://daily.dev/tags/vibe-coding), [#appsec](https://daily.dev/tags/appsec), [#supabase](https://daily.dev/tags/supabase)

[View this post on daily.dev](https://daily.dev/posts/some-supabase-customers-are-publicly-exposing-reams-of-people-s-data-to-the-web-ftusoweiz)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Some Supabase customers are publicly exposing reams of people’s data to the web","url":"https://daily.dev/posts/some-supabase-customers-are-publicly-exposing-reams-of-people-s-data-to-the-web-ftusoweiz","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/some-supabase-customers-are-publicly-exposing-reams-of-people-s-data-to-the-web-ftusoweiz"},"datePublished":"2026-09-25T17:34:41.695Z","dateModified":"2026-09-25T18:15:32.366Z","description":"Security firm UpGuard found roughly 16,000 Supabase-hosted databases publicly exposing personal data, including names, addresses, phone numbers, and passwords,...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/9ec694a6ed28a369e72737ce60b0855f?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/9ec694a6ed28a369e72737ce60b0855f?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"TechCrunch","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"TechCrunch","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/tc","url":"https://daily.dev/sources/tc"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/some-supabase-customers-are-publicly-exposing-reams-of-people-s-data-to-the-web-ftusoweiz","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"vibe-coding,appsec,supabase","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"TechCrunch","item":"https://daily.dev/sources/tc"},{"@type":"ListItem","position":3,"name":"Some Supabase customers are publicly exposing reams of people’s data to the web"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/some-supabase-customers-are-publicly-exposing-reams-of-people-s-data-to-the-web-ftusoweiz#faq","mainEntity":[{"@type":"Question","name":"Why are so many Supabase databases leaking personal data publicly?","acceptedAnswer":{"@type":"Answer","text":"Security research from UpGuard found around 16,000 Supabase-hosted databases exposing personal data such as names, addresses, phone numbers, and passwords, largely due to misconfigured access controls rather than a platform vulnerability. Many of these apps were vibe-coded using AI tools, which can generate code with security flaws or require configuration steps developers are unaware of, leaving row-level security or API access improperly locked down. Anyone shipping a vibe-coded app on supabase can use daily.dev to stay ahead of similar data-exposure lessons."}},{"@type":"Question","name":"Is Supabase secure by default for storing user data?","acceptedAnswer":{"@type":"Answer","text":"Supabase's Chief Information Security Officer Bil Harmer states that projects are secure by default, describing security as a shared responsibility where Supabase provides secure defaults and tooling while customers control their own project configuration. Despite this, independent research has repeatedly found large-scale data exposures across Supabase-hosted projects, including cases affecting Y Combinator startups and other popular apps. Developers weighing backend platforms for sensitive data can track supabase security debates on daily.dev."}}]}
```

