Jennifer Lawrence, Robert De Niro, Martin Scorsese, Francis Ford Coppola, Angelina Jolie, Guillermo del Toro, Ron Howard, Morgan Freeman, Rami Malek, Eva Mendes and Michael J. Fox are among the Hollywood celebs whose details allegedly got exposed in a massive data breach involving the Tribeca Festival. The leak got revealed after a cybersecurity researcher said an unsecured online database contained more than 666,000 records, including contact information associated with thousands of entertainment industry professionals. Festival organisers have argued that much of the data was public business contact information, but the discovery has sparked renewed concerns about how organisations store sensitive information and how exposed databases can
become targets for cybercriminals.Accordng to Variety, the records allegedly contained names, email addresses, phone numbers and mailing addresses of prominent filmmakers, actors and entertainment professionals. A number of the entries appeared to have been written by assistants, managers or publicists, rather than the celebrities themselves, cybersecurity researcher Jeremiah Fowler noted, with other records being incomplete.
How was database found?
Jeremiah Fowler, who works with Black Hills Information Security and publishes research through ExpressVPN, said he discovered the exposed database using an internet-connected device search engine that is often described as a search tool for publicly-accessible servers and cloud storage. The database contained 666,369 records with time stamps from 2019 through 2026, Fowler said.Most of the files were understood to be routine festival items, such as marketing assets, promotional images and press documents. However, Fowler also found a backup dump file that contained a folder called "contacts" with over 13,000 entries.
Information was public, says Tribeca
The leak was met with pushback from parts of the Tribeca Festival following the results. Festival representatives said no personal contact information belonging directly to celebrities had been disclosed. The vast majority of the exposed records were publicly available business contact information, such as talent reps, publicists, front office email addresses and information already published through official festival channels, the organization said.The exposed data was deleted quickly after the organisation was notified, the organisation also said.
Mistake in exposure
The root problem, Fowler said, was not some sophisticated cyberattack, but a basic configuration error. He said a backup file was apparently stored in a production database and not taken to a secure offline storage location. More importantly, the backup file was unencrypted, meaning anyone who found the database on the internet could read its contents.Since the data was publicly available, Fowler said it could have been accessed using an ordinary web browser, without needing sophisticated hacking methods.He added that he found no evidence that cybercriminals had previously accessed the database, noting that systems exposed for long periods of time are often accompanied by ransomware messages or signs of malicious activity, which were absent in this case.
AI's risky role
A lot of the records may have been business contacts, but Fowler warned that even harmless information can become useful in the age of artificial intelligence. AI tools can be used to combine emails, names and information about organisations to create convincing phishing campaigns that target specific individuals.Fowler said that modern AI systems have lowered the bar for cybercrime by making it easier for people without much tech know-how to generate complex phishing emails or malicious documents. Instead of trying to break into secure systems, attackers can simply use information that is publicly available to pose as a trusted contact or organisation.He added that Tribeca acted swiftly after the exposure was reported, taking down the information that was made accessible shortly after being notified.