PrivacySignal
Breach

A-list directors, actors and celebrities exposed in Tribeca film festival data leak

DataBreaches.net · · International · Data Breaches

Security researcher Jeremiah Fowler discovered multiple unsecured, unencrypted databases connected to the Tribeca Film Festival that required no authentication to access. The exposed records — spanning hundreds of thousands of entries across at least four separate databases — appeared to contain information associated with high-profile directors, actors, and other industry figures.

Why this matters: This was not a sophisticated attack. Nobody broke in. The door was open. That is actually the more common story in data exposure, and it is the more embarrassing one. The people in these records did not choose to hand their information to anyone who found the right URL. Celebrities and public figures still have private details — travel, contacts, financial arrangements — that can be used against them. The festival collected that data and left it sitting out. If you are trusted with people's information, locking it is the minimum obligation, not an optional extra.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
The Record · · International

Electronic health record company says customer data stolen in breach

Veradigm, an electronic health record company, disclosed that customer data was stolen in a breach affecting a specific interface. The company stated the incident did not spread to its broader infrastructure and caused no operational disruptions.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
BleepingComputer · · International

Veradigm warns of patient data breach after ransomware gang claims attack

Veradigm, a healthcare technology company, has disclosed a data breach affecting patient personal data following a cyberattack on one of its third-party vendors. A ransomware group has claimed responsibility for the incident.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · General readers · Policy

#breach#healthcare#privacy#security Read original →
Breach
WIRED — AI · · International

A Stealth Startup Thinks It Just Hacked the Memory Shortage

Kepler Computing, a stealth-stage chip startup, says it has developed a new design approach and a proprietary material that could ease the memory supply shortages driving up prices across the semiconductor industry.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

“Network outage” disrupts Westfield Public Schools in New Jersey as ransomware group posts samples

Joseph Topping reports: Westfield Public Schools in New Jersey kept classrooms open during a districtwide network outage that disrupted communications and digital instruction throughout the first week of school. The district initially attributed the outage to equipment failure. “We have confirmed that a networking hardware failure caused the disruption across all district schools and offices,”... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
FTC Consumer Protection · · US Federal

FTC Withdraws Obsolete Policy Statement

The FTC has rescinded its 2021 Policy Statement on health app data breach notification, saying the statement became redundant after the agency updated its Health Breach Notification Rule in 2024 to formally cover health apps and connected devices. The withdrawal aligns with a Trump executive order directing agencies to remove unnecessary regulatory guidance.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · Lawyers

#breach#healthcare#regulation Read original →
Breach
EDPB · · EU

Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR

France's data protection authority, the CNIL, fined Hôpital Privé de la Loire €500,000 after an attacker gained unauthorized access to its centralized patient records system in summer 2025. The hospital was found in violation of GDPR rules on security of processing and breach notification to affected individuals.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals · General readers · Policy

#breach#enforcement#healthcare#privacy Read original →