UpGuard's research, reported by TechCrunch, found that these databases were accessible due to basic security misconfigurations by developers using Supabase. The exposed data included private conversations from an Indian adult streaming site, thousands of license plates from a U.S. valet service, and authentication tokens. Supabase, which reached a $10 billion valuation earlier this year, has faced criticism over its security posture. The company has seen a surge in usage as developers increasingly rely on AI tools to rapidly build and deploy 'vibe-coded' apps, often without proper security awareness.
This pattern echoes a long history of data breaches linked to improperly configured storage servers, which have previously leaked sensitive military emails, immigration applications, and children's personal data. UpGuard said its goal was to understand the scale of exposure across the platform, and found that the databases hosted by Supabase contained a range of personal information, though passwords and authentication tokens were less common.