UpGuard finds 16,000+ misconfigured Supabase databases leaking user data
Cyber risk firm UpGuard scanned around 300,000 domains using Supabase and found more than 16,000 databases with misconfigured access controls exposing readable tables. Over half contained personally identifiable information, with smaller subsets exposing plaintext passwords, authentication tokens, and in some cases credit card data. Specific examples cited include a US valet service exposing 100,000+ customer records, a Canadian immigration service leaking 884 plaintext passwords, and an African government consulate exposing 25,000 records.