Security researcher Jeremiah Fowler discovered four publicly accessible databases containing nearly 666,000 records linked to the Tribeca Film Festival, exposing contact information associated with prominent Hollywood figures including Angelina Jolie, Robert De Niro, Martin Scorsese, George Lucas, and Danny Boyle. The exposed data included names, phone numbers, email addresses, and device information spanning from 2019 through 2026. Fowler alerted the festival shortly before its 12-day event began on June 3, prompting an investigation and removal of the databases from public access.
The Tribeca Film Festival, founded in New York by Robert De Niro and others, has become a major annual cultural event attracting industry professionals and celebrities. The exposed databases appear to have been used for professional communication and coordination related to the festival. While high-profile names appeared in the records, sources indicate that most of the leaked contact information belonged to managers and agents representing celebrities rather than the stars' personal accounts.
The exposed records included technical details beyond basic contact information. One folder reportedly contained device information associated with email addresses, revealing details such as iPhone versions, browser types like Safari, and installed software versions. This metadata could provide attackers with additional context for crafting targeted phishing campaigns or malware attacks tailored to specific devices and software configurations.
The scope and duration of the exposure remain unclear. It is unknown how long the databases were publicly accessible before Fowler's discovery, whether unauthorized individuals accessed or copied the data, and if any information has been misused. The festival has not provided detailed public information about the incident beyond confirming it takes data security seriously and is actively investigating. There is no indication that the Tribeca Film Festival was directly responsible for the misconfiguration.
Organizations managing databases containing information about public figures and industry professionals should implement access controls, conduct regular security audits, and monitor for unauthorized exposure. Even when exposed records primarily contain professional contacts rather than personal information, such breaches can reveal relationships between celebrities and their representatives, creating opportunities for social engineering attacks. Security teams should verify that databases are not publicly accessible and ensure proper authentication mechanisms are in place before storing sensitive professional contact information.
Source: https://thecyberexpress.com/tribeca-film-festival-data-breach/


