Skip to main content
Emerging ThreatsData Breaches

Tribeca Film Festival Data Leak Reveals Celebrity Records

Server equipment sits in a brightly-lit office, symbolizing data security.

"Thank you for bringing this information to our attention. We appreciate your responsible disclosure. Tribeca takes matters of data security very seriously and is actively investigating this issue," the festival's contacts told cybersecurity researcher Jeremiah Fowler after he reported an exposed database.

Three unsecured databases tied to the Tribeca Film Festival

According to cybersecurity researcher Jeremiah Fowler, records associated with the Tribeca Film Festival were exposed in three publicly accessible, unsecured databases labeled “development,” “staging,” and “production.” The three collections together totaled 666,369 records: 203,370 in “development,” 224,999 in “staging,” and 238,000 in “production.” Timestamps on the records ranged from 2019 to 2026.

Contents of the “production” database: contact data and hashed passwords

Fowler reported that inside the “production” database there was a file containing multiple types of sensitive information. The exposed fields included phone numbers, email addresses, IP addresses, and hashed passwords. The presence of hashed passwords and networking identifiers in a production export marks that set apart from the other two environments.

“Contacts” file lists names and physical addresses of high-profile film figures

Also among the exposed material was a document named “contacts” that displayed names, phone numbers, email addresses, and physical addresses. Fowler identified several well-known film industry celebrities in that list by name, including Martin Scorsese, Guillermo del Toro, George Lucas, Winona Ryder, Robert De Niro, and Morgan Freeman.

Response to disclosure and the next immediate step

Fowler said he sent a responsible disclosure notice to festival contacts. He reported receiving the quoted reply in which the festival acknowledged the notice, expressed appreciation for the responsible disclosure, and stated it was actively investigating the issue. That reply is the only documented public response recorded in Fowler's disclosure as reported.

What this means for technologists, the general public, and event organizers

  • Technologists and security teams: The presence of three environment copies—“development,” “staging,” and “production”—with separate record counts highlights the need to track and secure non-production copies of data the same way production is handled. The researcher’s finding that the “production” set contained phone numbers, emails, IP addresses, and hashed passwords draws attention to how production exports can carry high-value identifiers.
  • End users and the general public: The exposed “contacts” file included names and physical addresses of named film figures and contact information for others. Individuals named in that dataset will likely want clarity on which specific fields were exposed and whether any follow-up notifications or protections will be offered as the festival investigates.
  • Event organizers and festival procurement leaders: The leak underscores the practical reality that database labeling (development/staging/production) does not by itself ensure separation or security. Those responsible for festival systems and vendors that manage attendee or talent contact data will need to account for copies of datasets that may persist across environments.

Closing observation

The exposed set spans 2019 through 2026, comprises 666,369 records across three environments, and includes a production export with phone numbers, email addresses, IP addresses, and hashed passwords alongside a “contacts” document naming high-profile film figures. The festival’s acknowledgement that it is “actively investigating” follows a responsible disclosure; what remains to be seen is how the investigation will characterize the exposure, whether affected individuals will be notified beyond the researcher’s contact, and what remediation steps will be taken for the three named databases.

Original reporting: https://www.securitymagazine.com/articles/102473-film-festival-data-leak-exposes-a-list-directors-actors-celebrities