Summary
- Four databases linked to Tribeca reportedly exposed 666,369 records dating from 2019 to 2026.
- The material included contact information, IP addresses, account records, and bcrypt-hashed passwords.
- Ownership, exposure duration, external access, and the accuracy of individual celebrity records remain unclear.
Four databases containing records associated with Tribeca Festival were publicly accessible without a password, exposing contact information and account data connected to film-industry professionals, applicants, staff, and prominent public figures.
Security researcher Jeremiah Fowler reported finding separate databases labelled development, staging, production, and contacts. Together, they contained an estimated 666,369 records spanning 2019 to 2026.
The production database reportedly held 238,000 records, while an accessible backup contained email addresses, telephone numbers, internet-protocol addresses, user records, film contacts, and bcrypt-hashed passwords. The development and staging environments each held more than 200,000 records.
Fowler said entries carried the names of actors and directors including Angelina Jolie, Robert De Niro, Martin Scorsese, Jennifer Lawrence, Morgan Freeman, Michael Douglas, Rami Malek, Sharon Stone, George Lucas, and Danny Boyle.
A name in a contact database does not establish that every telephone number or email address belonged directly to the named person. Some entries may have referred to managers, assistants, agents, professional representatives, historic contacts, duplicate names, or publicly available business information.
Fowler notified Tribeca, and access was restricted on the same day. Tribeca told the researcher that it was investigating. The organisation has not publicly established how long the databases were exposed, whether another party accessed them, or whether the systems were operated directly by Tribeca, Tribeca Enterprises, or a supplier.
The researcher’s disclosure report does not provide evidence that the information was used maliciously. The available facts support describing the event as a data exposure rather than a confirmed hostile intrusion.
Contact details linked to well-known people can support impersonation, targeted phishing, account-recovery fraud, harassment, or approaches designed to appear as though they came from a trusted colleague or representative. Device and network information can add context to those attempts.
Test environments carried production data
The presence of development, staging, and production databases points towards a broader data-governance failure. Non-production systems are often treated as lower risk, although they may contain copied customer records, backups, debug information, test accounts, or historic information retained for convenience.
A database named “contacts” may appear operationally ordinary, but its sensitivity depends on the people and relationships it contains. Film festivals bring together performers, directors, agents, journalists, sponsors, employees, volunteers, applicants, suppliers, and guests, creating a relationship map that can support highly targeted social engineering.
Muhammad Yahya Patel, vCISO and cybersecurity adviser at Huntress, said the exposure reflected an ordinary configuration failure rather than a complex intrusion.
“No sophisticated attack, no nation-state actor, no zero-day exploit. Just a misconfiguration that anyone with a browser and basic knowledge could have stumbled across.”
Internet exposure can bypass substantial investment in endpoint controls, identity security, and monitoring when a datastore is deployed without authentication. External asset monitoring, configuration review, and clear ownership are needed to identify systems that sit outside the controls applied to the main application.
Backups require separate attention because they frequently fall outside ordinary access controls. A production database may enforce authentication through an application, while a copied dump is stored in a location that can be retrieved directly. Encryption at rest offers little protection where the storage service grants anonymous access to the data.
Retention also determines impact. Contact and account records accumulated across several years increase the number of affected people when a configuration fails. Organisations need defensible deletion schedules, separation between production and test data, synthetic development datasets, and inventories covering every database and backup.
Where suppliers host event, accreditation, submission, ticketing, or customer-relationship systems, contractual controls should cover access configuration, logging, deletion, incident notification, and evidence that non-production environments do not contain unnecessary personal data.
Tribeca’s investigation will need to establish ownership, access history, affected individuals, regulatory obligations, and whether credentials or contact information require protective action. Until that work is complete, claims that every named individual was directly compromised would exceed the evidence available.




