Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

Over 16,000 Supabase Databases Leak PII, Passwords, and Auth Tokens

UpGuard identified more than 16 000 publicly readable Supabase databases exposing personal data, passwords and tokens. The breach highlights a control‑management gap that continuous assurance programs must monitor and evidence.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
5 sector(s)
✅
Actions
3 recommended
📰
Source
bleepingcomputer.com

Over 16,000 Supabase Databases Leak PII, Passwords, and Auth Tokens

What Happened — Researchers at UpGuard scanned ~300 k domains that appeared to use Supabase and discovered more than 16 000 publicly readable databases. The exposed tables contained personally identifiable information, plaintext passwords, authentication tokens and, in a few cases, credit‑card data.

Why It Matters for Trust & Control Assurance

  • This is a textbook example of a configuration‑management control gap that a continuous control‑assurance program is built to detect, remediate, and evidence.
  • Without automated verification of row‑level security policies and proper key handling, organizations cannot prove they meet the “secure configuration” objective across any framework.
  • The incident shows why continuous evidence collection (e.g., automated scans, audit logs) is essential to demonstrate due‑diligence to auditors and regulators.

Who Is Affected — Companies of any size that rely on Supabase for back‑end services: retail/valet operators, government agencies, media platforms, OTP providers, and other SaaS developers.

Recommended Actions

  • Inventory every Supabase instance and verify that row‑level security policies are enabled.
  • Deploy automated configuration‑validation tooling that continuously monitors database permissions and public‑key usage.
  • Capture and retain evidence of remediation steps to satisfy audit requirements. Source: https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/

Technical Notes

  • Attack vector: misconfiguration – missing or ineffective row‑level security policies and misuse of public keys.
  • Data types exposed: PII (names, contact info, license plates), plaintext passwords, authentication tokens, limited credit‑card numbers, private messages. Source: https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/
📰 Original Source
https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →