Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-27 · updated: 2026-09-27 · tags: [incident, retail] · confidence: high · severity: critical · affected_sectors: [retail] · au_impact: true

Security researchers at UpGuard identified around 16,000 databases hosted by the development platform Supabase on which some degree of personal data was publicly readable, in findings first reported by TechCrunch on 25 September. The affected projects are largely consumer and small-business applications built on the platform's hosted Postgres offering, and the common thread is configuration rather than a flaw in Supabase itself: access controls left at permissive defaults expose tables through the platform's auto-generated APIs. Supabase, which reached a US$10 billion valuation earlier in 2026 on the strength of AI-assisted and "vibe-coded" app development, has faced repeated criticism over how much of its security posture is delegated to the developer; this is the largest published sample of that misconfiguration class, following earlier documented cases at other hosting and backend services where millions of records each were left readable. For organisations that have shipped a small AI-built internal or customer-facing app in the past year, the practical checks are whether row-level security is enabled, whether public keys grant more than read access to intended tables, and whether anyone owns the security of the deployment at all.

Attribute Detail
Sector Retail & Entertainment & Sport
Date 2026-09-27
Source UpGuard
Reliability Tier 1