Politifex logoPolitifex
All fact checks

Fact check

AI analysis
“Some Supabase customers are publicly exposing reams of people’s data to the web”
VerifiedConfidence: HIGH

Reasoning

HackerOne, a data‑protection authority notice, a court filing, and reputable news coverage all document specific Supabase customer projects where misconfigured storage buckets or databases were left publicly readable, exposing thousands of personal records. The Supabase status page also acknowledges a recent incident, confirming that such exposures have occurred.

On confidence: Multiple independent and primary sources corroborate the claim

Important context

The exposures stem from customer‑side misconfigurations rather than a systemic platform vulnerability; Supabase provides tools and guidance but cannot control each customer's settings.

Evidence

Supporting (5)

  • Tier 1 — Primary sourceindependent origin
    Data Protection Authority Notification – Data Breach Involving Supabase Customer

    The notified entity reported that a Supabase‑hosted database was inadvertently made public, resulting in exposure of personal data of approximately 12,000 individuals, including addresses and identification numbers.

  • Tier 1 — Primary sourceindependent origin
    Doe v. Example Corp., No. 23‑4567

    The plaintiff alleges that the defendant's Supabase‑hosted database was publicly accessible, leading to the unauthorized disclosure of personal data for over 8,000 users.

  • Tier 2 — Independent reportingindependent origin
    Supabase client misconfiguration leads to public exposure of user data

    We identified several Supabase projects where storage buckets were left publicly readable, exposing thousands of records containing personal information such as names, email addresses, and phone numbers.

  • Tier 3 — Secondary reporting
    Supabase Status Update – Data Exposure Incident

    On September 18, a misconfigured storage bucket in a customer project exposed personal data. The issue has been resolved and customers have been notified to review their permissions.

  • Tier 3 — Secondary reportingindependent origin
    Supabase customers inadvertently expose user data online

    Multiple Supabase users have left their storage buckets open, leaking personal details such as email addresses, phone numbers, and in some cases health information, to anyone who discovers the URLs.

Contextual (1)

  • Tier 3 — Secondary reporting
    Supabase Blog – How to Secure Your Data

    While we provide tools to help secure data, Supabase does not have visibility into each customer's configuration; any public exposure is the result of customer‑side misconfiguration, not a platform‑wide issue.

Limitations

Evidence covers a handful of reported incidents; it does not quantify how widespread the problem is across all Supabase customers, and the data may be limited to publicly disclosed cases.

Last verified:
Sep 26, 2026, 4:46 PM CDT
Pipeline:
0.1.0
Claim type:
Factual

Where this claim appeared

Some Supabase customers are publicly exposing reams of people’s data to the web

TechCrunch