Tribeca Festival Hack 2026: 666,369 Records Exposed, Including Celebrity Contacts

The Tribeca Festival spent 2026 celebrating its 25th anniversary, a milestone meant to honor a quarter-century of rebuilding Lower Manhattan’s cultural scene after 9/11. The programming was typical Tribeca: 118 feature films, 103 world premieres, and the usual A-list parade through downtown. That celebration now has a shadow hanging over it.

A cybersecurity researcher discovered that a backup file containing 666,369 records from the festival had been sitting exposed online. The timestamps on that file run from 2019 to 2026, so this wasn’t a one-time slip. It was a data exposure that went unnoticed for years. And buried inside that unprotected file was a folder with contact information for some of the biggest names in Hollywood: Martin Scorsese, Francis Ford Coppola, Jennifer Lawrence, Angelina Jolie, Robert De Niro, and more.

Key Takeaways

Security researcher Jeremiah Fowler discovered a backup file containing 666,369 records with timestamps from 2019 to 2026, left unencrypted in a production environment, via an IoT search engine.

The exposure included 13,535 entries in a “contacts” folder with names, addresses, phone numbers, and emails of celebrities like Martin Scorsese, Jennifer Lawrence, Angelina Jolie, and Robert De Niro, plus some assistants and publicists.

The festival says most data was public-facing business contact info and disputes the severity, but there’s no evidence anyone else accessed the data before Fowler found it.

The Scope of the Leak: 666,369 Records Over Seven Years

Here’s the number that matters: 666,369 exposed records. That’s the total sitting in an exposed backup file, and the timestamps show data going back to 2019. That’s not a small slip or a temporary misconfiguration. That’s seven years of accumulated data left unprotected.

But here’s the nuance that gets lost in the headline: most of that data wasn’t sensitive. The bulk of it was routine stuff, things like marketing materials, press kits, and promotional images. If your first instinct is to picture a million people’s credit card numbers and social security details, that’s not what happened here. The majority of that file was the kind of promotional noise that a festival generates across seven years.

The real problem was the part of that file that was sensitive. That’s where the story gets uncomfortable.

The backup.dump File and the “contacts” Folder

A backup file does exactly what the name suggests: it holds a copy of data so you can recover it if something goes wrong. But there’s an unspoken rule in any competent security setup, and it’s dead simple: you don’t keep the backup sitting in the same production environment where the live data lives. That defeats the entire purpose. If someone gets into the production system, they get the backups too.

Computer screen showing backup.dump file with contacts folder highlighted, representing the Tribeca data leak
The exposed backup file contained a ‘contacts’ folder with thousands of entries, including personal details.

That’s exactly what happened here. Fowler found a backup.dump file, essentially a raw archive of everything in one place, completely unencrypted, sitting in plain text in the production environment. And inside that dump file was a folder called “contacts” containing 13,535 entries.

That folder is where the sensitive stuff lived. We’re talking names, physical addresses, phone numbers, and email addresses. The file wasn’t a list of LinkedIn-style business connections. It was contact data for people who likely assumed their home addresses weren’t sitting in an exposed file.

The messy part? Some of those entries were incomplete. Some didn’t belong to celebrities at all, but to assistants, managers, and publicists. That’s its own kind of problem.

The exposure didn’t just touch famous people. It touched the people around them, the support staff whose job is to make themselves accessible while keeping their bosses protected.

Who Was Affected

The ‘contacts’ folder read like a guest list for a Tribeca gala. Besides Scorsese, Coppola, Lawrence, Jolie, and De Niro, the folder contained entries for Guillermo del Toro, Ron Howard, Morgan Freeman, Rami Malek, Eva Mendes, and Michael J. Fox.

That’s not a complete list. It’s enough to make the situation clear. These aren’t anonymous data points in a marketing database. These are specific people whose physical addresses and phone numbers were sitting in an unencrypted file.

The festival’s position is that this data was business contact information. But the distinction matters. A publicist’s office number is business contact info. A personal Gmail address or a home address tucked into a contacts folder is something else, even if it was collected for work purposes. Fowler says he found plenty of consumer email accounts in there, Gmail and Yahoo addresses, the kind of personal accounts that suggest the line between professional and private contact information got blurry.

How the Leak Was Discovered

The story turns absurd here. Fowler didn’t crack the festival’s security or exploit a sophisticated vulnerability. He was scanning the internet using an IoT search engine. That’s basically Google for websites, except it indexes connected devices and exposed databases instead of blog posts and news articles.

Security researcher discovering the Tribeca data leak while scanning the internet
The leak was found not by a targeted hack, but by a researcher scanning the web for exposed databases.

You can hear the randomness in Fowler’s discovery. He wasn’t targeting a film festival. He was scanning for connected devices and stumbled onto something he wasn’t looking for. That’s how a lot of exposed data gets found, not by hackers with sophisticated tools, but by accident.

Fowler’s background gives him credibility on this. He’s been in the security field for roughly 15 years, runs security for a software company in Kyiv, and publishes his findings via the ExpressVPN blog. His read on the situation is blunt: this was human error, not a sophisticated attack. Someone left a backup file left unencrypted in a production environment. That’s the kind of mistake that security people talk about when they say the simplest failures cause the worst damage.

He also saw no evidence that anyone else had accessed the data before he found it. That’s the one piece of good news in this story.

The Festival’s Response and the Dispute Over Sensitivity

Here’s where the story gets complicated. The festival didn’t shrug this off. They responded, and they responded fast. Fowler himself commended them for handling it quickly and professionally, which is rare in these situations.

Their statement, though, pushed back on the severity. The festival said that most of the information was public-facing business contact details. They asserted that no personal contact information of talent was disclosed. They said the information was removed promptly upon discovery.

Fowler disagrees. The ‘contacts’ folder existed, it had 13,535 entries, and it included personal email accounts like Gmail and Yahoo, not just work contacts. He also said the festival disputed some of his findings by phone, not just in the formal statement.

So who’s right? It’s not fully reconcilable from the available reporting. The festival says the data was mostly public-facing business info. Fowler says the contacts folder contained more personal detail.

Both claims can’t be fully true, but neither party is obviously lying either. The truth is probably somewhere in between, with the festival understating the sensitivity of some entries and Fowler seeing the worst-case version of what was exposed.

What’s not in dispute: a backup file holding a contacts folder with 13,535 entries was left unencrypted in a production environment. Everything else is spin.

Why It Matters

Fowler’s rule about backups is the whole lesson in one sentence: you don’t keep a backup file in the production environment. That’s not a sophisticated security principle. It’s basic hygiene. It’s the equivalent of leaving a spare key under the doormat and then being surprised someone found it.

The timing makes this worse. Fowler’s warning about AI adds a forward-looking edge to the story. Exposed personal data is more dangerous now than it was five years ago because AI tools let anyone craft convincing phishing attacks. You don’t need to be a skilled scammer to send an email that looks like it’s from a legitimate contact.

You just need the right address book and a decent language model. That’s the risk. The data in that folder could be used to target celebrities, their assistants, their managers, and anyone else whose contact details were in there.

There’s also a broader point here that goes beyond Tribeca. Any organization holding contact data on high-profile people is a target. The exposure of physical addresses and phone numbers matters regardless of whether the festival considers it “business contact info.” A celebrity’s home address is not public-facing information just because it’s in a business contact file. The people in that folder deserve the same privacy expectations as anyone else, maybe more given the risks that come with fame.

And the caveat that matters: there’s no evidence the data was misused before Fowler found it. He didn’t see any evidence of anyone else accessing it. That’s the silver lining. But that’s also the story with exposed data.

The lack of evidence of misuse doesn’t mean it didn’t happen. It means we don’t know. Once a file like that is accessible, you can’t un-expose it. You can only hope nobody found it first.

Background: What the Tribeca Festival Is

To understand why this matters, you need to understand what the festival means to New York. Tribeca was co-founded in 2002 by Robert De Niro, Jane Rosenthal, and Craig Hatkoff with a specific mission: spur the economic and cultural revitalization of Lower Manhattan after 9/11. This wasn’t just a film festival. It was a statement that downtown New York would come back.

The scale is large. The festival hosts over 600 screenings and draws roughly 150,000 attendees annually. It premiered ‘The Avengers’ and ‘The Handmaid’s Tale.’ It awarded ‘Let the Right One In.’ This is a major cultural institution, not a niche gathering.

Spring Studios at 50 Varick Street became the main venue in 2015. The festival dropped “Film” from its name in 2021 and added a video games category that year, a nod to how the event had broadened beyond cinema. In 2020, when COVID forced a cancellation, the festival pivoted to digital programming and a drive-in series, showing it could adapt when the world changed underneath it.

The 2026 edition was the payoff for all that resilience. The 25th anniversary ran June 3-14, featuring 118 feature films and 86 shorts, with 103 of those features having their world premieres. ‘Cotton Fever’ took Best U.S. Narrative Feature, and ‘Labrador: Autopsy of Silence’ won Best International Narrative Feature.

A festival born to help a neighborhood recover from a national tragedy now faces a security failure of its own making. The contrast is sharp, and Fowler’s conclusion is the one that sticks: “The purpose of my report and findings are not to throw organizations under the bus.” Then why publish? To show where the vulnerabilities are. To get organizations to fix them before someone else finds them first.

The data is out. The file was exposed. The only question now is whether anyone found it before Fowler did. And nobody can answer that with certainty.

Frequently Asked Questions

What is the Tribeca Festival data leak?

A backup file containing 666,369 records, including a contacts folder with 13,535 entries, was left unencrypted in a production environment. The data included names, addresses, phone numbers, and emails of celebrities and their associates, and was discovered by security researcher Jeremiah Fowler.

How was the Tribeca Festival data leak discovered?

Security researcher Jeremiah Fowler found the exposed backup file while scanning the internet using an IoT search engine, which indexes connected devices and exposed databases. He was not specifically targeting the festival but stumbled upon the unencrypted file.

What did the Tribeca Festival say about the data leak?

The festival responded quickly and said most of the information was public-facing business contact details, asserting that no personal contact information of talent was disclosed. They also said the information was removed promptly upon discovery, but Fowler disputes the severity, noting the presence of personal email accounts.

Why is the Tribeca Festival data leak significant?

The leak is significant because it exposed personal contact information of high-profile individuals, which could be used for targeted phishing attacks, especially with AI tools that make crafting convincing emails easier. It also highlights a basic security failure: keeping a backup file in the production environment.

Photo of author

Noman

Noman covers automotive news and reviews for Unfinished Man. His passion for cars informs his in-depth assessments of the latest models and technologies. Noman provides readers with insightful takes on today's top makes and models from his hands-on testing and research.

Leave a Comment