PrivacySignal
Breach

A-list directors, actors and celebrities exposed in Tribeca film festival data leak

DataBreaches.net · · International · Data Breaches

Security researcher Jeremiah Fowler discovered multiple unsecured, unencrypted databases connected to the Tribeca Film Festival that required no authentication to access. The exposed records — spanning hundreds of thousands of entries across at least four separate databases — appeared to contain information associated with high-profile directors, actors, and other industry figures.

Why this matters: This was not a sophisticated attack. Nobody broke in. The door was open. That is actually the more common story in data exposure, and it is the more embarrassing one. The people in these records did not choose to hand their information to anyone who found the right URL. Celebrities and public figures still have private details — travel, contacts, financial arrangements — that can be used against them. The festival collected that data and left it sitting out. If you are trusted with people's information, locking it is the minimum obligation, not an optional extra.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

Breach
DataBreaches.net · · International

AU: Sydney nurse accused of downloading patients’ data in alleged ‘breach of trust’

A registered nurse in northern Sydney has been charged after allegedly accessing and downloading patient records from NSW Health without authorisation. Police formed a dedicated strike force and conducted a home search following a report made in late July.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →
Breach
DataBreaches.net · · International

No Need to Hack When It’s Leaking: Click to Pray edition

Click to Pray, a papal-endorsed prayer app with hundreds of thousands of users globally, exposed users' names and email addresses for an extended period — potentially months or longer. An ethical hacker discovered and reported the leak.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

ShinyHunters data leaks fuel $2,000 sextortion email scam

Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
WIRED — AI · · International

The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days

OpenAI models used in an attack on Hugging Face, a major AI model-sharing platform, were reportedly active on the internet for several days before the intrusion was detected or stopped. The incident adds to growing scrutiny of how AI systems can be weaponized against the infrastructure that supports AI development itself.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
F Fox Business · · International

AI innovation is outpacing governance, leaving companies exposed, EqualAI warns

EqualAI, an AI governance nonprofit, has warned that the rapid pace of AI development is moving faster than the policies and oversight structures companies have in place to manage it, leaving organizations legally and reputationally vulnerable.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
BleepingComputer · · International

OnTrac notifies customers of data breach after network hack

OnTrac, a regional parcel delivery company, has begun notifying customers that unauthorized actors broke into its corporate network and may have accessed their personal information. The company has not publicly detailed what data was exposed or how many people are affected.

Who should care: Cybersecurity · Privacy officers · Administrators