AI-Built Apps Leaked Data From Thousands of Users
A researcher found about 16,000 Supabase databases with exposed personal data: passwords, addresses, private messages. The cause was mistakes in apps, some of which were built with AI.
Security researcher Greg Pollock of UpGuard found about 16,000 databases on Supabase, a platform valued at 10 billion dollars, exposed to the open internet with real personal data: names, addresses, passwords, and access tokens. The leaks included private messages from users of an Indian streaming service, thousands of license plate numbers from a US parking service, and a database belonging to an African consulate in France. The cause was mistakes in apps, some of which were written with the help of AI.
In this case, an agent wrote code that worked, but it never locked down the basic access settings for the database. Real passwords and private messages leaked as a result. For me, this is one more reason not to trust that an app just runs. I check database access rights separately before showing it to anyone but myself.
Source: techcrunch.com
Free course
Stop reading about AI — start building with it
The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.
Start free →▌ Related guides

Author
Evgenii Arsentev
PhD · Chief Executive Officer, digital health
Articles · Latest articles