Tribeca Festival data leak exposed Jennifer Lawrence, Robert De Niro contacts
A reported Tribeca Festival data leak exposed hundreds of thousands of records, including celebrity-linked contacts. The festival disputed that stars' personal details were revealed, while the researcher warned of phishing risks.
by India Today Entertainment Desk · India TodayIn Short
- Cybersecurity researcher Jeremiah Fowler found the unsecured database during a routine search
- Most exposed files were marketing materials, press kits and promotional images
- A backup contacts folder reportedly held over 13,500 names and addresses
The Tribeca Festival reportedly suffered a major data leak that exposed more than 666,000 records, including contact details linked to several Hollywood stars, according to a report by Variety. The exposed database allegedly contained information connected to actors such as Jennifer Lawrence, Angelina Jolie, Robert De Niro, Morgan Freeman and filmmakers Martin Scorsese and Francis Ford Coppola.
The leak was discovered by cybersecurity researcher Jeremiah Fowler, who said he found the unsecured database using an internet-connected device search engine. Speaking to Variety, Fowler said he has spent around 15 years looking for exposed online data and identified the database during a routine search.
According to Fowler, most of the exposed files consisted of marketing material, press kits and promotional images. However, a backup file reportedly contained a "contacts" folder with more than 13,500 entries, including names, email addresses, phone numbers and postal addresses. He noted that some records appeared to belong to assistants, managers or publicists rather than the celebrities themselves, while some fields were incomplete.
The Tribeca Festival disputed parts of Fowler's findings. In a statement quoted by the publication, a spokesperson said none of the celebrities mentioned had their personal contact information exposed. The festival maintained that most of the data contained publicly available business contact details, including those of talent representatives, publicists and front-office email addresses, and added that the information was removed soon after it was brought to its attention.
Fowler told the publication that the incident appeared to be the result of human error, claiming that an unencrypted backup file had been left accessible within the production database. He said that because the information was not encrypted, it could be viewed by anyone with an internet connection using publicly available search tools.
Despite criticising the security lapse, Fowler praised the festival's response, saying it acted "very fast and professionally" after being informed of the issue. He also said he found no evidence that the database had been accessed by cybercriminals before it was secured.
Fowler further warned that such data leaks pose greater risks in the age of artificial intelligence, as AI tools can make phishing attacks and other cyber scams easier to carry out. He stressed that his work is intended to help organisations identify security weaknesses rather than embarrass them publicly.
- Ends