What Happened
UpGuard researchers examined about 300,000 domains showing signs of Supabase use and found more than 16,000 exposed databases. The root cause is missing or ineffective row-level security policies and misuse of public keys. More than half of the exposed databases held personally identifiable information. A smaller set held passwords and authentication tokens, and a small number held possible payment card data. UpGuard traced a common thread. Many of these sites were built by AI coding agents, and the humans who shipped them did not know how the database was configured. Victims include a US valet service with more than 100,000 customer records and a Canadian immigration service with about 5,000 user records, 884 of them with plaintext passwords. Read the full report at BleepingComputer.
Why This Matters for Canadian Organizations
An exposed immigration service database is a Canadian problem in plain view. It holds identity details tied to people at a vulnerable point in their lives. Under PIPEDA, an organization must report a breach involving a real risk of significant harm to the Office of the Privacy Commissioner and notify affected individuals. It must also keep a record of every breach. Quebec’s Law 25 adds its own incident duties. Plaintext passwords raise the stakes, because people reuse them across banking, email, and government portals.
The wider lesson is about speed. Canadian startups, agencies, and internal teams now ship apps built with AI assistants in days. The assistant writes working code, but it does not guarantee a safe database policy. Responsibility for the data stays with the organization collecting it.
What to Do
List every Supabase project your teams and contractors run, including prototypes. Turn on row-level security for every table and review each policy for the anonymous role. Keep the service role key off the client side. Store no plaintext passwords, and use managed authentication. Add a configuration review to your release checklist for any AI-generated code. If you find exposed data, start a breach assessment and rotate credentials right away.
See more technical breakdowns in our TechTalk section and daily updates in News.






