Find notable cyber news and cases, enriched with sources, timelines, and signals.

Misconfigured Supabase databases exposing readable tables with sensitive data

Data Leak
First reported
Last updated
Happening score
H score 67
1 unique sources, 1 articles

Summary

Hide ▲

Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with PII, passwords, and authentication tokens. A smaller subset also appears to include credit card data, widening the potential fallout beyond account takeover. The exposure is tied to missing or ineffective row-level security and misuse of public keys, and application owners were notified when significant exposure was identified.

Related Happenings

Moltbook Supabase database exposure

Data Leak
H score45 First: 08.02.2026 09:32 Last: 08.02.2026 09:32 Sources 1

About this happening: A misconfigured Supabase database exposed Moltbook data, putting API authentication tokens, email addresses, and private messages at risk of unauthorized acces...

Moltbook AI social platform data leak from exposed Supabase API key

Data Leak
H score32 First: 03.02.2026 12:00 Last: 03.02.2026 12:00 Sources 1

About this happening: The Moltbook AI social platform suffered a data leak after an exposed Supabase API key gave unauthenticated access to its production database. The exposure put 1...

Timeline

  1. 28.09.2026 21:50 2 articles · 2h ago

    Misconfigured Supabase databases expose readable tables with sensitive data

    Technical Analysis Update

    UpGuard found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, authentication tokens, and a small set of possible credit card data. The exposed databases included nearly 5,000 user records at a Canadian immigration service with 884 plaintext passwords, more than 100,000 customer records at a U.S. valet service, more than 100,000 private messages at an India-based adult creator platform, more than 2,000 users and 100,000 SMS messages at a Philippines-based OTP service, and records for 25,000 people at an African government consulate. UpGuard attributed the exposure to missing or ineffective row-level security policies and misuse of public keys, and said it notified application owners when significant exposure was identified.

    Show sources