16,000 App Databases Were Left Wide Open. No Hacking Required.
On September 25, 2026, security firm UpGuard reported that it had found roughly 16,000 databases, all hosted on the popular app platform Supabase, exposing personal data to anyone on the internet. Names, home addresses, phone numbers, and passwords were readable without hacking anything, because the apps' own developers had left the doors unlocked. If you have signed up for a newer app or website in the past few years, there is no practical way for you to know whether yours was one of them. What you can control is how much damage an exposure like this does: unique passwords for every account, less personal detail handed to apps you barely use, and fewer places where your address and phone number are already published for anyone to cross reference.
What did UpGuard actually find?
UpGuard scanned roughly 300,000 domains showing signs of Supabase use and found 16,326 databases with tables anyone could read. About 16,000 of them exposed some degree of personal data. The examples were not limited to hobby projects: researchers reported a database belonging to an African government's consulate in France, and another used by a virtual SIM farm to intercept one time passcodes, the kind of operation used to launch scams. Most of the exposed data appeared to be tied to the United States, though UpGuard described it as a worldwide problem. Earlier research had already turned up exposed Supabase databases belonging to Y Combinator startups and other popular apps.
Supabase is not the villain in a simple sense. It is a widely used service that stores data for web and mobile apps, and its chief information security officer told TechCrunch the company provides secure defaults and that security is shared between Supabase and the customers who configure their own projects. The core problem is a single setting. Supabase relies on a feature called Row Level Security to decide who can read each table. When a developer creates a table without it, the table can be read by anyone holding the app's public key, which ships inside the app itself.
Why are AI built apps making this worse?
Building an app used to take a team months. Today a single person can describe an app to an AI coding tool and have something working in a weekend. That is genuinely useful, and it also means apps are reaching real users without anyone on the team who understands database security. The AI writes code that works. Working and safe are different tests. Coverage of the UpGuard research has highlighted how AI generated and so called vibe coded apps can expose user data when nobody configures them properly.
From your side of the screen, nothing looks different. A slick signup page tells you nothing about whether the table holding your address has a lock on it. That is the uncomfortable lesson of this research: the quality of an app's design is no signal at all about the quality of its data handling. We cover the broader version of this problem, apps collecting more than they need and passing it on, in how apps track and sell your data.
Will you be told if your data was in one of these databases?
Possibly not. An exposure like this often comes to light only because an outside researcher finds it. If the developer cannot show who accessed the data, or is a one person project with no process for notifying anyone, you may simply never hear about it. That is why this kind of leak feels abstract and is actually dangerous. Exposed records get scraped, merged with other leaks, and resold in bundles. Our explainer on whether your information is on the dark web covers where that material tends to end up.
The fields named in this research, name, address, phone, password, are worth looking at closely. A leaked password is dangerous mainly if you reuse it. A leaked email invites phishing, which we cover in what someone can do with your email address. But name, address, and phone number are exactly the fields people search sites already publish openly. A scammer holding a leaked login can type your name into one of those sites and confirm your current address, your age, and your relatives in seconds. The leak gives them a starting point. The broker listing finishes the job.
What can you do when you cannot see the leak?
You cannot audit someone else's database, so work on what you can control. Most of this is free.
- Stop reusing passwords. A password manager makes unique passwords painless. This one habit neutralizes most of the damage from any leaked login, from any app, forever.
- Check whether your email appears in known breaches. Have I Been Pwned is free. It will not catch every exposure, but it shows you which accounts to fix first.
- Give new apps less. If a habit tracker asks for your home address or birthday, it does not need them. Use an email alias for low trust signups so a leak does not expose your main inbox.
- Delete accounts you no longer use. An account you forgot about is still a row in someone's table.
- Shrink your public footprint. Remove your address and phone number from people search sites, so a leaked name cannot be turned into a location with a single search.
On that last point, consistency decides the result. Consumer Reports found that manual and automated opt out methods removed only about 27 percent of the listings it was tracking, while services using real people who monitored and resubmitted removals reached roughly 70 percent. Brokers refresh their data constantly, so a one time cleanup fades.
We cannot lock a stranger's database. We can stop them finding your door.
To be clear about the limit: Privoria cannot delete your data from a misconfigured app, retrieve anything already scraped, or make any developer secure their tables. Nobody outside that company can. What we do is remove the public layer that makes leaked data dangerous: your address, phone number, age, and relatives on people search and data broker sites. Our team files each removal by hand, verifies it, and refiles when listings come back. Run a free scan to see what a stranger holding a leaked login could look up about you right now.
Should you stop trusting small apps?
Not entirely, and not because of one platform. Big companies leak data too, and plenty of small developers are careful. The better takeaway is to treat every app as a place your data might eventually spill, and to decide what you hand over with that in mind. Assume exposure, limit what each app knows, and make sure the information that matters most, where you sleep at night, is not sitting in public waiting to be matched against whatever leaks next.
Frequently asked questions
How do I find out if an app I use was in the Supabase exposure?
There is no public list, and UpGuard did not publish one, which is responsible practice. Your best options are to watch for notices from apps you use, check your email on Have I Been Pwned, and assume that any detail you gave a small or new app could be exposed someday.
Is Supabase unsafe to use?
The research points to how customers configured their databases, not to a break in Supabase itself. Tables protected with Row Level Security were not the issue. For you as a user, the platform name matters less than whether the developer did the setup properly, which you cannot see.
Was anyone actually hacked?
No hacking was needed, which is the point. The data was publicly readable. Whether criminals copied any specific database before researchers found it is generally unknown, so it is safest to assume exposed data may have been taken.
Can Privoria delete my data from these databases?
No. Only the company running an app can delete data from its own database. We remove your listings from people search and data broker sites, which is the public information that lets someone connect a leaked record to your current home and phone.