Data Breaches Neutral 5

666,369 Records Unsecured: Tribeca Festival Database Exposed Online

A publicly accessible database at Tribeca Festival held contact details for A-list celebrities, discovered by researcher Jeremiah Fowler via an IoT search engine, underscoring the entertainment industry's lax cloud security.

· 3 min read · Verified by 2 sources ·
Share

Key Takeaways

  • A publicly accessible database at Tribeca Festival held contact details for A-list celebrities, discovered by researcher Jeremiah Fowler via an IoT search engine, underscoring the entertainment industry's lax cloud security.

Mentioned

Angelina Jolie person Tribeca Festival company Jeremiah Fowler person Jennifer Lawrence person Martin Scorsese person

Key Intelligence

Key Facts

  1. 1A database containing 666,369 total records was left publicly accessible online, with files dating from 2019 to 2026.
  2. 2A 'contacts' folder held over 13,500 entries, including names, addresses, phone numbers, and email addresses of A-list celebrities and their teams.
  3. 3High-profile individuals affected include Angelina Jolie, Jennifer Lawrence, Martin Scorsese, Robert De Niro, Morgan Freeman, and others.
  4. 4Cybersecurity researcher Jeremiah Fowler discovered the exposed database using an IoT search engine, indicating no authentication was in place.
  5. 5Tribeca Festival stated the breach did not expose private personal information, attributing records to marketing and public contacts.
Exposed Records
666,369 +

Database uncovered without authentication, spanning 2019–2026

Analysis

From a cybersecurity perspective, the Tribeca Festival incident is a stark reminder that even high-profile events neglect basic cloud security hygiene. A database of 666,369 records, including names, addresses, and emails of celebrities like Angelina Jolie, sat exposed for years—accessible to anyone with an IoT search engine. Threat actors could leverage this data for targeted phishing, social engineering, and physical security risks.

In July 2026, a routine scan by cybersecurity researcher Jeremiah Fowler uncovered a publicly accessible cloud database linked to New York's Tribeca Festival, exposing 666,369 records — including sensitive contact information of A-list celebrities like Angelina Jolie. The database, left without authentication, contained files from 2019 to 2026, with a dedicated 'contacts' folder holding over 13,500 entries. While most data consisted of marketing and promotional materials, the contact records revealed names, physical addresses, phone numbers, and email addresses of some of Hollywood's most recognizable figures, such as Jennifer Lawrence, Martin Scorsese, Robert De Niro, and Morgan Freeman.

If California residents were among the affected, the California Consumer Privacy Act (CCPA) allows statutory damages of $100 to $750 per consumer per incident.

The exposure raises profound questions about data stewardship in the entertainment sector, where the fusion of celebrity culture and weak cybersecurity hygiene creates a lucrative target for malicious actors. Fowler found the database using a simple IoT search engine — essentially a search tool for connected devices — indicating a failure of even rudimentary access controls. This was not a sophisticated breach but a configuration oversight, a recurring theme in cloud storage leaks across industries.

Legally, Tribeca Festival now faces potential liability under multiple privacy regimes. Given its international attendee list, the database almost certainly included European residents, triggering the EU's General Data Protection Regulation (GDPR) with its stringent 72-hour breach notification mandate and fines of up to 4% of annual global turnover. If California residents were among the affected, the California Consumer Privacy Act (CCPA) allows statutory damages of $100 to $750 per consumer per incident. New York's SHIELD Act, with its 'reasonable safeguards' requirement, further complicates the festival's position. Tribeca's response — that the leak did not expose 'private personal information' — may be an attempt to minimize liability by arguing that much of the data was business contact details (agents, publicists). However, in a celebrity context, such distinctions can be blurry; a manager's phone number can lead directly to the star, and home addresses of high-profile individuals carry grave security risks.

What to Watch

From a cybersecurity standpoint, the incident highlights the persistence of legacy databases and the entertainment industry's lag in adopting enterprise-grade security. Data spanning eight years left publicly accessible suggests a gap in asset discovery and routine audits. Threat actors could exploit the verified contact metadata for spear-phishing campaigns or social engineering, using the festival's brand to build trust. Celebrity phishing lures are already common in business email compromise schemes; this breach provides fresh, credible data. The researcher's ethical reporting is a silver lining, but the data may have already been copied by automated scanners that continuously probe for open storage.

Broader implications extend to the entire event management ecosystem. Film festivals, awards shows, and conventions rely on temporary staff and ad-hoc systems, often without dedicated security teams. This breach serves as a wake-up call to adopt frameworks like NIST or ISO 27001, enforce encryption, and implement access controls. The incident may also spur regulatory scrutiny, particularly in New York, and could chill celebrity participation in public events if trust in data handling erodes. Ultimately, the Tribeca leak is not just a privacy lapse but a test case for how legal liabilities will be assigned in an era where even non-traditional data controllers must safeguard personal information.

Sources

Sources

Based on 2 source articles

Cite This Page

"666,369 Records Unsecured: Tribeca Festival Database Exposed Online." Cyber Intelligence Brief, July 28, 2026. https://getcyberbrief.com/story/tribeca-database-exposure-cyber-risk

How we covered this story

Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.