# UpGuard finds more than 16,000 Supabase databases with readable tables that expose personal data > UpGuard scanned about 300,000 domains using Supabase and found over 16,000 databases with readable tables, some holding passwords; AI-assisted development is common among new ones. FireAI Security & Research Team (HisnLabs) ยท Published 2026-09-30 Canonical: https://hisnlabs.com/en/news/upguard-16000-supabase-databases-expose-personal-data UpGuard has reported more than 16,000 misconfigured Supabase databases whose tables could be read by outsiders, [BleepingComputer reported](https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/) on 28 September 2026. The exposed tables include personal information, and in a smaller share of cases passwords and authentication tokens [[1]](https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/). ## Background Supabase is a hosted database service that many small applications use behind their web or mobile front end. It can restrict which rows a visitor may read through row-level security policies. When those policies are missing or ineffective, a key that the app ships publicly can be used to read the tables directly. AI coding tools make it faster to build an app with such a back end, which is why the report draws attention to AI-assisted development. ## What the report describes UpGuard's researchers scanned about 300,000 domains that show signs of using Supabase, tried to read database tables and examined the table structures to identify the kinds of data exposed. They found more than 16,000 databases with readable tables. UpGuard reports that more than half of the exposed databases contained personally identifiable information, and that more than six in ten newly created databases involve AI-assisted development [[1]](https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/). Examples given include more than 100,000 customer records at a United States valet service, 5,000 user records at a Canadian immigration service including 884 passwords stored in plain text, and 25,000 records at an African government consulate. Other exposed data types include credit card data in limited cases, licence plates, visit histories, addresses, emergency-housing locations, private messages and SMS messages [[1]](https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/). The report attributes the problem to configuration errors, specifically missing or ineffective row-level security and misuse of public keys, and quotes UpGuard as saying that the people building the apps understand their business but not their database's configuration. UpGuard directs developers to Supabase's security documentation, its advisors and its API security guide [[1]](https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/). > FireAI, the on-device firewall for macOS developed by HisnLabs, shows which apps on a Mac send data to which companies and countries. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Implications for Mac users People whose details sit in a small service's database cannot see or fix its configuration, and the report does not say whether anyone other than the researchers read the exposed tables [[1]](https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/). Developers who build apps on a Mac with the help of an AI assistant are the group that can act, by checking access policies before launch. ## Recommendations 1. Developers should test their own tables while logged out, with only the public key, before release. 2. Turn on row-level security for every table and review the policies an AI assistant generated. 3. Never store passwords in plain text; use a managed authentication service. 4. Users should use a unique password for each small service and change it if a service reports exposure. ## Relevance to FireAI FireAI does not audit databases or repair the configuration of a service that holds a person's data, and it cannot stop an exposure on someone else's server. It is a network firewall for the Mac. It shows which apps connect to which services in [Activity](https://hisnlabs.com/en/docs/activity-and-connection-history), and the [world map](https://hisnlabs.com/en/docs/world-map) shows where in the world they are. A developer's Mac can therefore be checked for unexpected connections, but the fix for these exposures lies in the service's own settings. > Where an app sends data is visible on a Mac even when a server-side setting is out of reach. FireAI lists the destinations. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Limitations The findings rest on UpGuard's scan as summarised in one press report. A readable table is not proof that the data was accessed by others, and the examples are described without the affected organisations' names. The report does not say how many of the databases have since been closed. Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days. ## Sources - [BleepingComputer, 28 September 2026: Over 16,000 Supabase databases expose PII, passwords, auth tokens](https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/)