16,000 Supabase Databases Exposed to the Web Without a Login

About 16,000 databases hosted on Supabase exposed some personal data to the public internet, researchers at UpGuard found, as reported on Sept. 25, 2026. TechCrunch
Supabase gives web and app developers managed storage to store and run databases. It reached a $10 billion valuation earlier in 2026, as developers increasingly used it to host vibe-coded apps, programs largely drafted with AI coding help.
In the cases reviewed, names, addresses, phone numbers and user passwords could be read without logging in.
UpGuard described three examples. One held private conversations with sex workers from an Indian adult streaming site. Another held thousands of license plates from a U.S. valet service. A third held contact details for people who used an immigration and relocation service.
UpGuard also reported two other cases. One database belonged to an African government's consulate in France. The other supported a virtual SIM farm that intercepted text messages carrying one-time passcodes used to verify online accounts.
UpGuard said most exposed datasets appear to be in the United States, but called it a worldwide problem.
Supabase documentation advises users to turn on Row Level Security, the Postgres feature that limits which rows each user can see, and to write access policies that give apps only the minimum permissions they need. Supabase Docs The documentation states that Row Level Security controls access through a combination of grants and policies. Supabase Docs Separate guidance covers securing its Data API with Postgres grants, Row Level Security, dedicated schemas, and request checks. Supabase Docs
In practice, grants control which roles can touch a table, policies control which rows they can see, and schemas control which tables the API can reach. If tables sit in the public schema with permissive policies, the Data API and GraphQL API serve them as designed.
For new work, Supabase has changed the starting point. Starting April 28, 2026, customers can create projects where tables in the public schema are not automatically exposed to the Data API and GraphQL API. Supabase Changelog The company also published a 2025 security retrospective on platform changes made in 2025 and expectations for 2026. Supabase Blog
Worth flagging, the SIM farm case carries follow-on risk. Intercepted codes can be replayed against third-party logins, which allows account takeover elsewhere.
The broader context here is not specific to one vendor. Managed platforms cut the cost of shipping a backend to near zero. That also cuts the cost of shipping an insecure backend to near zero. When code generation speeds app building, setting access rules becomes the bottleneck. Developers test that data loads in the app, then ship.
In my view, the fix is procedural more than technical. Row Level Security and least-privilege policies belong in the starting template, not as a final hardening step. The April change helps new projects. The long tail is existing projects, forks, templates and tutorials that still carry open policies. For teams on managed Postgres, automated checks for anonymous read access, separation of public and private schemas, and regular review of active policies will catch more than any single default. The optimistic outcome remains. The same automation that created 16,000 exposures can enforce 16,000 corrections, if verification runs on every deploy.


