Over 16,000 Supabase databases expose PII, passwords, auth tokens

Refract AI Intelligence Digest

BLUF

16,000+ Supabase instances are leaking sensitive credentials and PII due to misconfiguration.

NEWS

Researchers identified over 16,000 Supabase databases with publicly readable tables containing PII, passwords, and auth tokens. The exposure results from improper security settings rather than a platform-level vulnerability. Affected organizations risk unauthorized access to their user data.

Why I Care

This incident exposes millions of users to identity theft and account takeover risks while damaging organizational trust. Developers relying on default configurations may unknowingly leave critical infrastructure open to attackers.

Next Steps

Supabase users must audit database permissions and enforce row-level security policies immediately. Security teams should rotate exposed credentials and scan for similar misconfigurations within the next 24 hours.

Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. [...]
Back to Blog Listing

Source: BleepingComputer ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.