Over 16,000 Supabase databases expose PII, passwords, auth tokens
BLUF
16,000+ Supabase instances are leaking sensitive credentials and PII due to misconfiguration.
NEWS
Researchers identified over 16,000 Supabase databases with publicly readable tables containing PII, passwords, and auth tokens. The exposure results from improper security settings rather than a platform-level vulnerability. Affected organizations risk unauthorized access to their user data.
Why I Care
This incident exposes millions of users to identity theft and account takeover risks while damaging organizational trust. Developers relying on default configurations may unknowingly leave critical infrastructure open to attackers.
Next Steps
Supabase users must audit database permissions and enforce row-level security policies immediately. Security teams should rotate exposed credentials and scan for similar misconfigurations within the next 24 hours.
Source: BleepingComputer ·