A-list directors, actors and celebrities exposed in Tribeca film festival data leak
Security researcher Jeremiah Fowler discovered multiple unsecured, unencrypted databases connected to the Tribeca Film Festival that required no authentication to access. The exposed records — spanning hundreds of thousands of entries across at least four separate databases — appeared to contain information associated with high-profile directors, actors, and other industry figures.
Why this matters: This was not a sophisticated attack. Nobody broke in. The door was open. That is actually the more common story in data exposure, and it is the more embarrassing one. The people in these records did not choose to hand their information to anyone who found the right URL. Celebrities and public figures still have private details — travel, contacts, financial arrangements — that can be used against them. The festival collected that data and left it sitting out. If you are trusted with people's information, locking it is the minimum obligation, not an optional extra.
Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.