The red carpet at Tribeca Film Festival photographs beautifully. The database infrastructure behind it? Not so much. Cybersecurity researcher Jeremiah Fowler recently reported discovering an unprotected, unencrypted database linked to the festival containing roughly 666,369 records spanning 2019 to 2026. No password. No encryption. Just a forgotten .dump backup file with what appears to be contact information tied to names like Martin Scorsese, Angelina Jolie, George Lucas, Jennifer Lawrence, and Robert De Niro — sitting on the open internet like an unlocked diary on a park bench.
What Was Actually Exposed
The database contained far more than press releases and screening schedules.
According to Fowler’s write-up on the ExpressVPN blog, the exposed records included:
- Email addresses, phone numbers, IP addresses, and hashed passwords inside a backup file
- Many emails using consumer services — Gmail, Yahoo, Outlook — suggesting personal rather than corporate accounts
- Operational data including schedules and press materials alongside the sensitive material
- Names reportedly linked to Robert De Niro, Morgan Freeman, Rami Malek, Hilary Duff, Neil Patrick Harris, Ron Howard, and Guillermo del Toro
Fowler contacted Tribeca immediately. The backup was removed the same day. Tribeca responded: “Tribeca takes matters of data security very seriously and is actively investigating this issue.” Who actually managed the database — Tribeca, Tribeca Enterprises, or a third-party vendor — remains unclear. Whether anyone else accessed the data before Fowler found it? Only a forensic investigation could answer that. “Backup files are some of the most overlooked when it comes to data security.” — Jeremiah Fowler, cybersecurity researcher.
Why This Goes Beyond Embarrassment
Leaked contact data for famous names has a thriving black market — and a grim history of real-world consequences.
FTC data shows impersonation fraud losses ballooned from $55 million in 2020 to $445 million in 2024. A leaked celebrity phone number is not just trivia — it is raw material for convincing fraud. One woman was reportedly scammed out of $850,000 by an AI-generated “Brad Pitt” persona, the deepfake equivalent of a Nigerian prince email but considerably more sophisticated.
And history carries darker weight. Actress Rebecca Schaeffer was murdered in 1989 after a stalker obtained her home address through a private investigator accessing DMV records. Her death helped reshape California privacy law — a reminder that contact data exposure for public figures has never been merely a privacy inconvenience.
A Pattern That Keeps Repeating
Entertainment organizations consistently handle high-value personal data with infrastructure that lags well behind the risk.
The Sony Pictures hack in 2014 exposed data on roughly 47,000 people. That same year, the iCloud breach hit Jennifer Lawrence directly — she later described it as a “sex crime.” The FTC’s 2025 Consumer Sentinel Network Data Book characterizes impersonation fraud as “one of the most pernicious and fast-growing forms of consumer fraud.” Each incident follows the same arc: glamorous brand, overlooked backend, serious fallout.
Security professionals consistently recommend two-factor authentication and unique credentials for every platform — especially where backup security practices are unknown. If your personal email has touched a registration form for any event or industry platform in recent years, that data may be sitting in a forgotten backup file somewhere. The organizations holding it may not be watching it as closely as you would hope for peace of mind.





























