Tribeca Film Festival Data Leak Exposes Celebrity Contact Details
Cybersecurity researcher Jeremiah Fowler says three unprotected Tribeca-linked databases exposed a folder of celebrity contact details, including phone numbers and email addresses for Angelina Jolie, Robert De Niro and Martin Scorsese.
Article record
Why it matters
What this means for organisations holding critical data
Cybersecurity researcher Jeremiah Fowler says three unprotected Tribeca-linked databases exposed a folder of celebrity contact details, including phone numbers and email addresses for Angelina Jolie, Robert De Niro and Martin Scorsese.
Cybersecurity researcher Jeremiah Fowler of Black Hills Information Security says he has uncovered what he calls the biggest collection of celebrity data he has ever seen, after finding three unprotected databases linked to the Tribeca Film Festival. The exposure was first reported by The Sun on Sunday and Daily Mail on 26 July 2026.
What Happened
Mr Fowler discovered three publicly accessible databases days before this year's Tribeca Film Festival opened. Most of the records, dated between 2019 and 2026, were marketing materials such as press releases stored on a cloud system. One of the databases, however, held a backup file containing a folder named "contacts" with personal information for high-profile guests and industry figures.
What Data Was Exposed
According to Mr Fowler, the contacts folder included names, phone numbers and email addresses. Celebrities reportedly named in the records include Angelina Jolie, Robert De Niro, Martin Scorsese, George Lucas, Danny Boyle, Neil Patrick Harris, Michael Douglas, Rami Malek and Sharon Stone. Mr Fowler told The Sun on Sunday there were "many, many household names in the records who could have been targeted with malware".
Why This Matters
Contact databases held in cloud backups are a recurring failure point. Once a bucket or backup file is misconfigured to public, every record it holds is readable by anyone who finds the URL, with no ransomware and no phishing required. For public figures the downstream risk is spear phishing, SIM swap fraud and physical stalking, not just spam.
The incident echoes a wider pattern in 2025 and 2026, where unsecured cloud storage, not sophisticated intrusion, has been the root cause of many of the largest personal data exposures.
High-Profile People Remain a Target
High net worth individuals, celebrities, senior executives and their advisers are not one-off targets. They are permanent targets. A single contact file is enough to map a person's inner circle, identify their gatekeepers, and craft attacks that look routine to a personal assistant or family office.
The risk is not theoretical. Leaked phone numbers and email addresses can be used to:
- Execute SIM swaps that bypass SMS-based authentication and empty accounts, or expose private messaging history.
- Launch spear-phishing campaigns against the assistants, lawyers and agents who handle day-to-day communications.
- Compile travel and location intelligence by cross-referencing leaked contacts with booking, transport and property records.
- Facilitate extortion or reputational attacks by piecing together relationships, schedules and private correspondence that should never have been public.
The attackers are not always sophisticated nation-state groups. Often they are opportunists who know that one well-known name opens doors to many others. When a film festival's contact database is left open, the value is not just the A-list names. It is the map of who knows whom, who handles what, and who can be pressured next.
For family offices, entertainment lawyers and talent managers, the lesson is the same: the data you hold on behalf of others is itself a target. The question is not whether a high-profile client will be attacked, but whether the information used to reach them is sitting on a public URL.
The Offline Alternative
Offline Secure Storage (OSS) is designed for exactly this class of record. Sensitive contact lists, unreleased schedules and privileged production files sit on physically air-gapped hardware inside a monitored bunker, retrieved only through identity-verified sessions during defined access windows. There is no public endpoint to misconfigure, no shared backup bucket to leave open, and no cloud console that an intern can toggle to "public" by mistake.
Key Takeaways
- Cloud backups are the new front door. Most large 2026 exposures have started with an unprotected backup, not a network intrusion.
- Contact data is high value. Names, phone numbers and email addresses for public figures fuel targeted malware and social engineering.
- High-profile targets are permanent targets. A leaked contact list is a map for follow-on attacks against the individual and their circle.
- Physical separation removes the failure mode. Air-gapped storage cannot be misconfigured to public because it is not on the public internet in the first place.
- Access should be a session, not a URL. Retrieval through identity-verified windows leaves an auditable trail; a public S3 link does not.
How Firevault would handle this
Physical disconnection removes the path an attacker needs
Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.






