Supabase databases are exposing sensitive personal data to the public web, according to new security research by UpGuard. The cybersecurity firm identified around 16,000 databases hosted by Supabase that had some degree of personal data exposed, raising concerns about user privacy and data security.

The exposed data includes publicly accessible names, addresses, phone numbers, and user passwords, according to UpGuard. The firm also found fewer passwords and authentication tokens, highlighting the scale of the issue.

The research uncovered databases linked to various projects, such as private conversations with sex workers on an Indian adult streaming site and thousands of license plates from a U.S. valet service.

One of the databases belonged to an African government’s consulate in France, while another was used to intercept text messages by a virtual SIM farm for sending one-time passcodes to verify online accounts, typically for launching scams and phishing attacks.

The findings suggest that the problem is not limited to the United States, as UpGuard noted this is a worldwide issue.

"We provide secure defaults and tooling, and customers control how their own projects are configured," said Supabase’s Chief Information Security Officer Bil Harmer. He emphasized that security is a shared responsibility between the company and its customers, and that Supabase notifies affected customers when security issues are discovered.

The findings build on earlier research that also found a range of exposed databases hosted on Supabase, including those by Y Combinator startups and other popular apps.

While Supabase has made changes to its platform over the years, including bolstering its security features, the company did not say how many of the exposed databases were its own or how many belonged to third-party developers.

Source: techcrunch