Your Team's "Vibe Coded" App Might Already Be Leaking Customer Data
A single security scan this week found over 16,000 publicly exposed databases built with AI coding tools — a wake-up call that the rush to build fast with AI is quietly creating a breach crisis for businesses of every size, not just tech giants.
A new wave of apps is getting built differently. Instead of hiring a development team or writing code line by line, business owners, marketers, and solo founders are increasingly describing what they want in plain English and letting an AI coding assistant generate the app for them — a practice now widely known as "vibe coding." It's fast, it's cheap, and it's putting working software in the hands of people who have never had it before.
It's also creating one of the more sobering cybersecurity stories of the year.
The Discovery: 16,000+ Exposed Databases
On October 1, 2026, cybersecurity research firm UpGuard published findings from a sweep of roughly 300,000 websites showing signs of using Supabase, a popular backend platform that AI coding tools lean on heavily because it's easy for an AI agent to wire up a database without human handholding. The results were striking more than 16,000 of those databases were publicly exposing readable data, no login required.
More than half contained personal information. A smaller but meaningful share exposed passwords or authentication tokens outright. A handful even showed plausible credit card data, and many more revealed signs of connected payment systems — the kind of access that could let an attacker quietly insert themselves into a transaction rather than just steal a list of names.
The exposures weren't limited to hobby projects. UpGuard's researchers found a real-world mix: an Indian content platform with passport and tax ID numbers for over 65,000 users; a Philippine one-time-password service with more than 100,000 exposed text messages; a U.S. valet parking company with records on over 100,000 customers; a government consulate's visitor database; and a relocation company storing 884 customer records with passwords saved in plain text.
The root cause wasn't a sophisticated hack. It was a default setting. Supabase, like many modern backend platforms, requires developers to explicitly turn on a feature called Row Level Security (RLS) to restrict who can read which rows of data. When an AI coding agent sets up a database through the platform's API — which is exactly how these tools are designed to work — that protection isn't switched on automatically. If nobody goes back to configure access rules correctly, the database is simply open to the internet. In several cases, teams also used a "public" API key in places that needed a private, secret one, compounding the exposure.
Why This Matters for Small and Mid-Sized Businesses
It's tempting to file this under "AI tools have growing pains" and move on. For an SMB leader, that would be a mistake, for three reasons.
First, this isn't a one-off bug — it's a structural pattern. AI coding assistants are explicitly built to work smoothly with platforms like Supabase because it reduces friction for non-technical users. That same ease-of-use is what skips the security step a trained developer would normally remember. As AI-assisted development keeps growing inside SMBs, marketing teams spinning up a customer portal, an operations lead building an internal tracking tool, a founder prototyping a new product, the odds that one of these tools touches sensitive data without a human double-checking access controls only go up.
Second, the businesses most exposed are exactly the ones least likely to have a security team watching for it. A development shop with trained engineers reviews infrastructure before launch. A five-person company using an AI builder to stand up a customer intake form usually doesn't have anyone whose job it is to ask, "did we turn on row-level security?" That gap is precisely where this kind of exposure thrives.
Third, exposed customer data is a compliance problem, not just an embarrassment. Depending on what's stored and who it belongs to, a leak like this can trigger state data breach notification laws, and for organizations handling healthcare, education, or government-adjacent data, it can implicate HIPAA, FERPA, or contractual security obligations tied to frameworks like NIST CSF or CIS Controls. Regulators and insurers increasingly don't care whether the mistake was made by a human developer or an AI agent the business that owns the data owns the liability.
SANS Institute researchers have been sounding a related alarm throughout 2026, noting that AI now sits at the center of the most dangerous attack and exposure patterns they track, and that the line between "AI-assisted convenience" and "AI-created risk" has largely disappeared. This Supabase finding is a textbook example: no malicious actor required, just a convenient default that nobody checked.
What SMBs Should Do This Week
You don't need to ban AI coding tools to get ahead of this. A few concrete, low-cost steps go a long way:
Inventory what's been built. Ask every team, not just IT, whether anyone has used an AI tool, no-code platform, or a service like Supabase, Firebase, or similar to stand up an app, form, or database in the last year. Shadow IT built by well-meaning employees is the whole problem here.
Verify access controls directly, don't assume. If your business or a vendor uses Supabase or a similar platform, confirm Row Level Security (or the equivalent access-control feature) is explicitly enabled and tested, not just left at default. Confirm that any "public" or client-facing API keys aren't being used anywhere a private key belongs.
Map this to a framework you already answer to. If you're tracking NIST CSF, the relevant controls sit squarely in the Protect function around access control and data security. If you follow CIS Controls, this is Control 3 (Data Protection) and Control 16 (Application Software Security) territory. Treating AI-built tools as in-scope for these controls, rather than exempt from them because "it's just a quick internal tool," closes the gap that caused this incident.
Build a review step into your AI-adoption policy. The fix isn't slowing down AI adoption it's adding one checkpoint before anything AI-built goes live with real customer data: a human who understands access control signs off first.
If your organization doesn't have the internal bandwidth to run that kind of review, that's precisely the gap a managed IT or cybersecurity risk partner is built to close not after an incident, but before one.
The Bottom Line
AI coding tools are not going away, and for most SMBs, they're a genuine advantage: faster builds, lower costs, less dependency on scarce technical talent. But this week's finding is a clear reminder that speed and security defaults are not the same thing, and the businesses that pair AI-assisted development with even basic security review will be the ones that capture the upside without becoming next month's breach notification.
