Over 16,000 Supabase Databases Leak PII, Passwords, and Auth Tokens
What Happened — Researchers at UpGuard scanned ~300 k domains that appeared to use Supabase and discovered more than 16 000 publicly readable databases. The exposed tables contained personally identifiable information, plaintext passwords, authentication tokens and, in a few cases, credit‑card data.
Why It Matters for Trust & Control Assurance
- This is a textbook example of a configuration‑management control gap that a continuous control‑assurance program is built to detect, remediate, and evidence.
- Without automated verification of row‑level security policies and proper key handling, organizations cannot prove they meet the “secure configuration” objective across any framework.
- The incident shows why continuous evidence collection (e.g., automated scans, audit logs) is essential to demonstrate due‑diligence to auditors and regulators.
Who Is Affected — Companies of any size that rely on Supabase for back‑end services: retail/valet operators, government agencies, media platforms, OTP providers, and other SaaS developers.
Recommended Actions
- Inventory every Supabase instance and verify that row‑level security policies are enabled.
- Deploy automated configuration‑validation tooling that continuously monitors database permissions and public‑key usage.
- Capture and retain evidence of remediation steps to satisfy audit requirements. Source: https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/
Technical Notes
- Attack vector: misconfiguration – missing or ineffective row‑level security policies and misuse of public keys.
- Data types exposed: PII (names, contact info, license plates), plaintext passwords, authentication tokens, limited credit‑card numbers, private messages. Source: https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/