A new Supabase data leak exposed databases at scale: researchers found 16,326 of them left open to the internet, with names, phone numbers, passwords and tokens readable by anyone who knew where to look. Supabase is a popular backend service that many apps use to store user data, so the problem is not one app failing but thousands of separate setups sharing the same kind of mistake.
This story matters to VPN users for an unexpected reason. Your VPN, your device and your own habits can all be sound, and your account details can still leak because an app you signed up for stored them carelessly. Here is what was reported, why it is dangerous, and what you can do about it.
What Researchers Found in the Exposed Supabase Databases
According to the reporting, 16,326 Supabase databases had publicly readable tables. Search coverage of the research attributes the finding to the cybersecurity firm UpGuard, and outlets covering it describe the affected projects as misconfigured rather than breached in the traditional sense.
That distinction is important. Nobody had to defeat a firewall or steal an administrator login. The data was sitting in tables that the internet could read. Coverage from TechCrunch frames the issue as one that shows how AI-generated and quickly built apps can spill users' data when they are not configured or secured properly.
The source article does not name the individual apps or the people affected, and we are not going to guess. What is clear is the scale: more than sixteen thousand separate databases, each potentially belonging to a different app with its own users.
Which Data Was Exposed and How It Enables Account Takeover
The exposed information included names, phone numbers, passwords and tokens. Each item is useful to an attacker on its own, and together they are far more dangerous.
- Names and phone numbers make phishing and text-message scams believable. A scammer who knows who you are and which app you use can send a convincing message.
- Passwords are the obvious risk. If you reused one on other services, a leak from a small app can open the door to your email or banking accounts.
- Tokens are less familiar but can be just as serious. A token is a digital key that proves you are logged in. Depending on how it is set up, a valid token may let someone act as you without ever needing your password.
That combination is what makes account takeover realistic. An attacker can try leaked passwords elsewhere, use a token directly, or use your contact details to trick you into handing over a verification code.
This follows a pattern we have seen before. When 24 billion credentials turned up in a publicly accessible database, the lesson was the same: exposed login data gets collected, reused and tried against other services.
Why Misconfigured Databases Keep Leaking User Data
Most people picture a data leak as a hacker breaking in. In practice, many leaks involve no hacking at all. As our explainer on how millions of records get exposed notes, a leak happens when information becomes accessible to people who were never meant to see it, often without any malicious break-in.
Backend services make it easy to launch an app quickly, and that speed can outrun security checks. If access rules for a database are left too open, or never fully set up, the data is readable from the outside. The user never sees this happen. The app looks fine on the surface.
We have covered similar cases. A misconfigured analytics dashboard tied to FTF Live left over 22 million session records openly accessible, and an unprotected Talentsconnect database exposed hiring data tied to more than 5 million job listings. Different companies, same root cause: something was left open.
The Supabase case adds a wrinkle. Because the same platform hosts thousands of small projects, one common mistake can be repeated thousands of times, and researchers can find them at scale. So can attackers.
What This Means For You
You usually cannot tell whether an app you use is one of the exposed ones. Apps rarely disclose which backend they use, and the reporting does not list affected apps. So the safest approach is to assume any small or new app could be a weak link and protect yourself accordingly.
It is also worth being honest about what a VPN can and cannot do here. A VPN encrypts your connection and hides your IP address from the sites you visit. It does not protect data that an app has already stored in an open database. If your password is sitting in a readable table on someone's server, your traffic being encrypted makes no difference. Privacy tools are still valuable, but they address a different problem.
Three Things to Do Today
- Reset reused passwords. If you use the same password on more than one service, change it now, starting with email, banking and any account that can reset others. A password manager makes unique passwords practical.
- Turn on two-factor authentication. Even if a password leaks, a second factor makes it much harder to use. Prefer an authenticator app over text messages where possible, since phone numbers were among the exposed data.
- Watch for misuse of your details. Use a credential monitoring service to check whether your email appears in known leaks, and treat unexpected texts or calls that mention your name or an app you use with suspicion. If an app offers a way to log out of all sessions, use it to invalidate old tokens.
The Bottom Line
The Supabase data leak exposed databases by the thousands, and the cause was misconfiguration, not a clever attack. That is both the bad news and the useful lesson: the weak point is often the backend behind an everyday app, not your device or your VPN. Update your passwords, enable two-factor authentication and keep an eye on your accounts. For more context, read our explainer on how data leaks happen and our report on the 24 billion exposed credentials for a reminder of why resets and monitoring matter.




