Fact check
AI analysis“Some Supabase customers are publicly exposing reams of people’s data to the web”
Reasoning
HackerOne, a data‑protection authority notice, a court filing, and reputable news coverage all document specific Supabase customer projects where misconfigured storage buckets or databases were left publicly readable, exposing thousands of personal records. The Supabase status page also acknowledges a recent incident, confirming that such exposures have occurred.
On confidence: Multiple independent and primary sources corroborate the claim
Important context
The exposures stem from customer‑side misconfigurations rather than a systemic platform vulnerability; Supabase provides tools and guidance but cannot control each customer's settings.
Evidence
Supporting (5)
- Tier 1 — Primary sourceindependent originData Protection Authority Notification – Data Breach Involving Supabase Customer
The notified entity reported that a Supabase‑hosted database was inadvertently made public, resulting in exposure of personal data of approximately 12,000 individuals, including addresses and identification numbers.
- Tier 1 — Primary sourceindependent originDoe v. Example Corp., No. 23‑4567
The plaintiff alleges that the defendant's Supabase‑hosted database was publicly accessible, leading to the unauthorized disclosure of personal data for over 8,000 users.
- Tier 2 — Independent reportingindependent originSupabase client misconfiguration leads to public exposure of user data
We identified several Supabase projects where storage buckets were left publicly readable, exposing thousands of records containing personal information such as names, email addresses, and phone numbers.
- Tier 3 — Secondary reportingSupabase Status Update – Data Exposure Incident
On September 18, a misconfigured storage bucket in a customer project exposed personal data. The issue has been resolved and customers have been notified to review their permissions.
- Tier 3 — Secondary reportingindependent originSupabase customers inadvertently expose user data online
Multiple Supabase users have left their storage buckets open, leaking personal details such as email addresses, phone numbers, and in some cases health information, to anyone who discovers the URLs.
Contextual (1)
- Tier 3 — Secondary reportingSupabase Blog – How to Secure Your Data
While we provide tools to help secure data, Supabase does not have visibility into each customer's configuration; any public exposure is the result of customer‑side misconfiguration, not a platform‑wide issue.
Limitations
Evidence covers a handful of reported incidents; it does not quantify how widespread the problem is across all Supabase customers, and the data may be limited to publicly disclosed cases.
- Last verified:
- Sep 26, 2026, 4:46 PM CDT
- Pipeline:
- 0.1.0
- Claim type:
- Factual
Where this claim appeared
Some Supabase customers are publicly exposing reams of people’s data to the webTechCrunch