Tribeca Festival Data Leak Exposes Contact Details for Hollywood's Biggest Stars

Tribeca Festival Data Leak Exposes Contact Details for Hollywood's Biggest Stars

A major data breach at the Tribeca Festival has left the contact information of thousands of celebrities potentially exposed, including some of Hollywood's most prominent figures. Cybersecurity researcher Jeremiah Fowler uncovered the leak, which involved more than 666,000 records with timestamps spanning from 2019 to 2026.

The Tribeca Festival was co-founded in 2002 by Robert De Niro, Jane Rosenthal, and Craig Hatkoff as part of an effort to revitalize Lower Manhattan following the September 11 attacks. The annual New York City event has hosted premieres ranging from "The Avengers" to "The Handmaid's Tale" and has recognized acclaimed films such as "Let the Right One In." The festival's 2026 edition, marking its 25th anniversary, ran from June 3 to 14.

How the Leak Was Discovered

Fowler, who works for Black Hills Information Security and publishes research through ExpressVPN, discovered the exposed data while using an IoT search engine — a tool he describes as essentially Google for connected devices such as cloud storage databases, medical equipment, and nanny cams. With roughly 15 years of experience in security research, Fowler was on a European vacation when he identified the vulnerability and took time to discuss his findings.

The exposed database contained a backup file stored in plain text without encryption, according to Fowler. He explained that the file had been left in a production environment, a practice he considers a significant oversight. Normally, backups are taken offline or stored in a separate database to serve as a fail-safe in case of system failures.

What the Data Contained

While much of the exposed material consisted of non-sensitive content such as marketing materials, press kits, and promotional images, Fowler identified a backup file that contained potentially sensitive information. Within that file, a folder labeled "contacts" held 13,535 entries containing names, addresses, phone numbers, and email addresses of well-known filmmakers and actors.

The list of individuals whose contact details appeared in the database includes Martin Scorsese, Francis Ford Coppola, Guillermo del Toro, Ron Howard, Robert De Niro, Jennifer Lawrence, Angelina Jolie, Morgan Freeman, Rami Malek, Eva Mendes, and Michael J. Fox. Fowler noted, however, that some entries were incomplete or contained contact information for assistants, managers, or publicists rather than personal details.

A separate document within the database contained approximately 135,000 contacts, which Fowler speculated belonged to individuals who had signed up for mailing lists or attended festival events.

Festival Response and Dispute

The Tribeca Festival issued a statement disputing some of the claims. A spokesperson asserted that none of the talent referenced in the reporting had personal contact information disclosed, and that the vast majority of the exposed data consisted of publicly available business contact information, including details for PR representatives, talent agents, and front office email addresses. The festival stated that all information was removed promptly upon discovery.

Fowler acknowledged that the festival disputed whether some of the contacts were personal or professional in nature. He countered by noting that he observed numerous consumer email accounts, including Google and Yahoo addresses, among the exposed data. Variety reported that it was still awaiting further comment from the festival, which had disputed some of Fowler's findings by phone.

Despite the disagreement over the nature of the exposed data, Fowler praised the festival's response speed and professionalism in addressing the issue once it was brought to their attention. He also reported finding no evidence of unauthorized access by other parties, noting that prolonged data exposures typically attract ransomware activity, which was absent in this case.

The Growing Threat of AI in Cybercrime

Fowler emphasized that the Tribeca Festival's error was fundamentally human — leaving an unencrypted backup file accessible to anyone with an internet connection. He noted that anyone could have created an account with an IoT search engine and viewed the data through a standard web browser such as Chrome, Firefox, or Safari.

He also highlighted the escalating risks posed by artificial intelligence in the cybersecurity landscape. According to Fowler, AI has effectively democratized hacking by enabling non-technical individuals to carry out sophisticated attacks. He described scenarios where AI tools could be used to generate phishing emails or create malware embedded in documents disguised as scripts, which could then be distributed to large numbers of people.

Fowler stressed that his objective is not to publicly shame organizations but to help them identify and address vulnerabilities. He pointed out that organizations that experience a data incident statistically tend not to have another for three to five years, as the experience typically prompts a renewed focus on penetration testing and vulnerability scanning.

As data breaches continue to make headlines across industries, the Tribeca Festival incident serves as a stark reminder of the importance of robust cybersecurity practices — even for organizations outside the technology sector. Have you ever considered how secure your own contact information is when signing up for events or mailing lists? Share this article with your network to help spread awareness about digital data protection.

Source: Variety