---
title: "Tribeca Film Festival Data Leak Exposes Celebri… | Firevault"
url: https://fire-vault.com/news/tribeca-film-festival-celebrity-contacts-leak-2026
description: "Cybersecurity researcher Jeremiah Fowler says three unprotected Tribeca-linked databases exposed a folder of celebrity contact details, including phone…"
lang: en-GB
---

News · Breach Analysis · 26 July 2026

# Tribeca Film Festival Data Leak Exposes Celebrity Contact Details

Cybersecurity researcher Jeremiah Fowler says three unprotected Tribeca-linked databases exposed a folder of celebrity contact details, including phone numbers and email addresses for Angelina Jolie, Robert De Niro and Martin Scorsese.

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-DWFWqeWL.jpg)

Mark Fermor CTO, CMO & Founder, Firevault

4 min read

Share

Share on LinkedIn: https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Ftribeca-film-festival-celebrity-contacts-leak-2026
Share on X: https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Ftribeca-film-festival-celebrity-contacts-leak-2026&text=Tribeca%20Film%20Festival%20Data%20Leak%20Exposes%20Celebrity%20Contact%20Details%0A%0ACybersecurity%20researcher%20Jeremiah%20Fowler%20says%20three%20unprotected%20Tribeca-linked%20databases%20exposed%20a%20folder%20of%20celebrity%20contact%20details%2C%20including%20phone%20numbers%20and%20email%20addresses%20for%20Angelina%20Jolie%2C%20Robert%20De%20Niro%20and%20Martin%20Scorsese.
Share on Facebook: https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Ftribeca-film-festival-celebrity-contacts-leak-2026

Image: Glowing broken padlocks over faint film reel silhouettes on a dark navy background (https://fire-vault.com/__l5e/assets-v1/7f57cb31-f45c-45ba-8861-ea7230f9f1c3/tribeca-film-festival-data-leak-2026-2x.jpg)

Glowing broken padlocks over faint film reel silhouettes on a dark navy background

Why it matters

## What this means for organisations holding critical data

Cybersecurity researcher Jeremiah Fowler of Black Hills Information Security says he has uncovered what he calls the biggest collection of celebrity data he has ever seen, after finding three unprotected databases linked to the Tribeca Film Festival. The exposure was first reported by The Sun on Sunday and Daily Mail (https://www.dailymail.co.uk/news/article-16006003) on 26 July 2026.

## What Happened

Mr Fowler discovered three publicly accessible databases days before this year's Tribeca Film Festival opened. Most of the records, dated between 2019 and 2026, were marketing materials such as press releases stored on a cloud system. One of the databases, however, held a backup file containing a folder named "contacts" with personal information for high-profile guests and industry figures.

## What Data Was Exposed

According to Mr Fowler, the contacts folder included names, phone numbers and email addresses. Celebrities reportedly named in the records include Angelina Jolie, Robert De Niro, Martin Scorsese, George Lucas, Danny Boyle, Neil Patrick Harris, Michael Douglas, Rami Malek and Sharon Stone. Mr Fowler told The Sun on Sunday there were "many, many household names in the records who could have been targeted with malware".

## Why This Matters

Contact databases held in cloud backups are a recurring failure point. Once a bucket or backup file is misconfigured to public, every record it holds is readable by anyone who finds the URL, with no ransomware and no phishing required. For public figures the downstream risk is spear phishing, SIM swap fraud and physical stalking, not just spam.

The incident echoes a wider pattern in 2025 and 2026, where unsecured cloud storage, not sophisticated intrusion, has been the root cause of many of the largest personal data exposures.

## High-Profile People Remain a Target

High net worth individuals, celebrities, senior executives and their advisers are not one-off targets. They are permanent targets. A single contact file is enough to map a person's inner circle, identify their gatekeepers, and craft attacks that look routine to a personal assistant or family office.

The risk is not theoretical. Leaked phone numbers and email addresses can be used to:

- **Execute SIM swaps** that bypass SMS-based authentication and empty accounts, or expose private messaging history.
- **Launch spear-phishing campaigns** against the assistants, lawyers and agents who handle day-to-day communications.
- **Compile travel and location intelligence** by cross-referencing leaked contacts with booking, transport and property records.
- **Facilitate extortion or reputational attacks** by piecing together relationships, schedules and private correspondence that should never have been public.

The attackers are not always sophisticated nation-state groups. Often they are opportunists who know that one well-known name opens doors to many others. When a film festival's contact database is left open, the value is not just the A-list names. It is the map of who knows whom, who handles what, and who can be pressured next.

For family offices, entertainment lawyers and talent managers, the lesson is the same: the data you hold on behalf of others is itself a target. The question is not whether a high-profile client will be attacked, but whether the information used to reach them is sitting on a public URL.

## The Offline Alternative

Offline Secure Storage (https://fire-vault.com/offline-secure-storage) (OSS) is designed for exactly this class of record. Sensitive contact lists, unreleased schedules and privileged production files sit on physically air-gapped hardware inside a monitored bunker, retrieved only through identity-verified sessions during defined access windows. There is no public endpoint to misconfigure, no shared backup bucket to leave open, and no cloud console that an intern can toggle to "public" by mistake.

## Key Takeaways

- **Cloud backups are the new front door.** Most large 2026 exposures have started with an unprotected backup, not a network intrusion.
- **Contact data is high value.** Names, phone numbers and email addresses for public figures fuel targeted malware and social engineering.
- **High-profile targets are permanent targets.** A leaked contact list is a map for follow-on attacks against the individual and their circle.
- **Physical separation removes the failure mode.** Air-gapped storage cannot be misconfigured to public because it is not on the public internet in the first place.
- **Access should be a session, not a URL.** Retrieval through identity-verified windows leaves an auditable trail; a public S3 link does not.

About the author

### Mark Fermor

Mark Fermor on LinkedIn (https://www.linkedin.com/in/mfermor)

CTO, CMO & Founder

Founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

Get started: https://fire-vault.com/get-started
Talk to the team: https://fire-vault.com/demo

**Hardware**Your copy sits on dedicated encrypted hardware

**Disconnect**Offline by default, connected only when you say so

**Recovery**A known-clean copy to rebuild from, on your timetable

**Location**Held in a secure Firevault Bunker

Related Reading

## You may also find these useful

Breach Analysis

### Dyfed-Powys Police confirms cyber attack as staff information may have been compromised

Dyfed-Powys Police has confirmed that a cyber attack identified on 14 September disrupted non-emergency systems and may have exposed staff information. The force says it has found no evidence that public data was accessed.

25 Sept 2026 3 min
https://fire-vault.com/news/dyfed-powys-police-cyber-attack-2026

Breach Analysis

### FBI investigates claims that hackers stole personnel and applicant data

The FBI is investigating unauthorised activity affecting its recruitment website after ShinyHunters claimed it stole sensitive records on current and former personnel and job applicants. The claimed scale remains unconfirmed.

22 Sept 2026 4 min
https://fire-vault.com/news/fbi-employee-applicant-data-breach-shinyhunters-2026

Breach Analysis

### Vulnerable children's health records caught up in HCRG Care Group cyber attack, families told 18 months later

Families of vulnerable children in Wiltshire, Bath and North East Somerset have been told their personal health information may have been accessed in a cyber attack on HCRG Care Group in February 2025, more than 18 months after the incident.

20 Sept 2026 4 min
https://fire-vault.com/news/hcrg-care-group-children-records-cyber-attack-2026

Breach Analysis

### FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters

US authorities boarded two foreign-flagged oil tankers in the Gulf of Mexico after indications their networks were compromised by foreign cyber actors. Mark Fermor on why a ship is a floating lesson in what happens when operational technology is reachable.

17 Sept 2026 4 min
https://fire-vault.com/news/fbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026

Breach Analysis

### FBI investigates 153 million drivers licenses put up for sale on a criminal forum

A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used by household names. The FBI has opened an inquiry, and the case shows how long retention turns a routine check into national-scale exposure.

16 Sept 2026 4 min
https://fire-vault.com/news/fbi-investigates-153-million-drivers-licenses-dark-web-2026

Breach Analysis

### CenterPoint Energy confirms hackers stole customer data through an exposed API

CenterPoint Energy has confirmed that criminals stole customer data through one of its external facing systems, after a threat actor advertised 7.49 million files on a dark web forum. Mark Fermor on what an unsecured API says about the way critical infrastructure treats connected data.

16 Sept 2026 4 min
https://fire-vault.com/news/centerpoint-energy-confirms-cyberattack-data-theft-2026

## Suggested Reading

- What is Offline Secure Storage The foundation of physical disconnection: https://fire-vault.com/how-it-works/offline-secure-storage
- Why Offline Secure Storage The case for physical control: https://fire-vault.com/why-oss
- Ransomware Defence Hold gold copies offline: https://fire-vault.com/oss-for-ransomware-recovery
- Control Physical path control for IT and OT: https://fire-vault.com/solutions/control
- Knowledge Vault All articles, guides and whitepapers: https://fire-vault.com/learn/knowledge
- Book a Demo See Firevault in action: https://fire-vault.com/demo

Back to Knowledge Vault: https://fire-vault.com/learn/knowledge

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/news/tribeca-film-festival-celebrity-contacts-leak-2026#webpage",
    "url": "https://fire-vault.com/news/tribeca-film-festival-celebrity-contacts-leak-2026",
    "name": "Tribeca Film Festival Data Leak Exposes Celebri…",
    "description": "Cybersecurity researcher Jeremiah Fowler says three unprotected Tribeca-linked databases exposed a folder of celebrity contact details, including phone…",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/__l5e/assets-v1/7f57cb31-f45c-45ba-8861-ea7230f9f1c3/tribeca-film-festival-data-leak-2026-2x.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/news/tribeca-film-festival-celebrity-contacts-leak-2026#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/news/tribeca-film-festival-celebrity-contacts-leak-2026#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Learn",
        "item": "https://fire-vault.com/learn"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Knowledge Vault",
        "item": "https://fire-vault.com/learn/knowledge"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "Tribeca Film Festival Data Leak Exposes Celebrity Contact Details",
        "item": "https://fire-vault.com/news/tribeca-film-festival-celebrity-contacts-leak-2026"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "NewsArticle",
    "headline": "Tribeca Film Festival Data Leak Exposes Celebrity Contact Details",
    "description": "Cybersecurity researcher Jeremiah Fowler says three unprotected Tribeca-linked databases exposed a folder of celebrity contact details, including phone numbers and email addresses for Angelina Jolie, Robert De Niro and Martin Scorsese.",
    "url": "https://fire-vault.com/news/tribeca-film-festival-celebrity-contacts-leak-2026",
    "image": [
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/7f57cb31-f45c-45ba-8861-ea7230f9f1c3/tribeca-film-festival-data-leak-2026-2x.jpg",
        "width": 1200,
        "height": 1200
      },
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/7f57cb31-f45c-45ba-8861-ea7230f9f1c3/tribeca-film-festival-data-leak-2026-2x.jpg",
        "width": 1200,
        "height": 900
      },
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/7f57cb31-f45c-45ba-8861-ea7230f9f1c3/tribeca-film-festival-data-leak-2026-2x.jpg",
        "width": 1200,
        "height": 675
      }
    ],
    "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/7f57cb31-f45c-45ba-8861-ea7230f9f1c3/tribeca-film-festival-data-leak-2026-2x.jpg",
    "author": {
      "@type": "Person",
      "name": "Mark Fermor",
      "jobTitle": "CTO, CMO & Founder",
      "worksFor": {
        "@id": "https://fire-vault.com/#organization"
      },
      "url": "https://fire-vault.com/why-oss/about"
    },
    "publisher": {
      "@type": "NewsMediaOrganization",
      "name": "Firevault",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 600,
        "height": 60
      }
    },
    "datePublished": "2026-07-26T18:00:00+00:00",
    "dateModified": "2026-08-28T08:03:22.256672+00:00",
    "mainEntityOfPage": {
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/tribeca-film-festival-celebrity-contacts-leak-2026"
    },
    "inLanguage": "en-GB",
    "articleSection": "Breach Analysis",
    "wordCount": 690,
    "keywords": "Tribeca, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
    "articleBody": "Cybersecurity researcher Jeremiah Fowler of Black Hills Information Security says he has uncovered what he calls the biggest collection of celebrity data he has ever seen, after finding three unprotected databases linked to the Tribeca Film Festival. The exposure was first reported by The Sun on Sunday and Daily Mail on 26 July 2026. What Happened Mr Fowler discovered three publicly accessible dat",
    "dateline": "United Kingdom",
    "speakable": {
      "@type": "SpeakableSpecification",
      "cssSelector": [
        "h1",
        ".article-summary",
        "h2"
      ]
    },
    "isAccessibleForFree": true,
    "copyrightHolder": {
      "@id": "https://fire-vault.com/#organization"
    },
    "copyrightYear": 2026
  }
]
```