Tribeca Film Festival data leak exposes Hollywood stars, including Angelina Jolie and Robert De Niro
Thousands of Hollywood contacts were exposed – and no one knows for how long.

Angelina Jolie. Laurent KOFFEL/Gamma-Rapho via Getty Images
- A publicly exposed Tribeca database revealed contact details tied to major Hollywood celebrities.
- The leak could give scammers a roadmap for highly targeted phishing attacks.
- Tribeca denies any celebrities' personal contact information was exposed.
- Four unsecured databases contained more than 666,000 records.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The contact information tied to thousands of A-list Hollywood stars was reportedly accessible to the public after a security researcher found several databases belonging to the Tribeca Film Festival leaking the private information – and no one knows how long the records were exposed.
Well-known security researcher Jeremiah Fowler with Black Hills Information Security said he recently discovered not just one, but 4 unsecured databases, exposing a combined 666,369 records.
Researcher finds exposed festival databases
Fowler, in a blog post written for ExpressVPN and first published over the weekend, said he found the first database – simply named “contacts” – days before the 2026 festival began on June 3rd.
A whopping 200,000 records – allegedly containing phone numbers, email addresses, and more – were linked to actors, directors, producers, media members, festival staff, and other industry professionals, he said.
“Tribeca Film Festival, A-list celebrities exposed in major data breach. I saw names such as Scorsese, Lucas, Ron Howard, De Niro, Morgan Freeman, Angelina Jolie, Jennifer Lawrence, Neil Patrick Harris, Hilary Duff, Rami Malek and many more,”Fowler revealed on X.
What’s wild is that Fowler also said the databases were publicly accessible without password protection or encryption before he notified the festival and they were subsequently secured the following day.
This means it's unclear how long the information was exposed or whether anyone else had accessed it before it was taken offline.
Notably, the records were said to be time-stamped with dates ranging from 2019 to 2026, a span of 8 years.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Fowler further acknowledged that it is unknown who was in charge of the database: the festival itself, its parent company Tribeca Enterprises, or a third-party vendor, contractor, or service provider.
Tribeca denies celebrity contact data leaked
Other Hollywood names found in the records were said to include Francis Ford Coppola, Michael Douglas, Kate Hudson, Eva Mendes, Steven Spielberg, Steven Tyler, Ethan Hawke, Bill Burr, Chace Crawford, and Jack Osbourne.
And the list doesn’t end there; Fowler also reported seeing contact information for Guillermo del Toro, Danny Boyle, Patty Jenkins, Winona Ryder, Naomi Watts, Don Cheadle, Debra Messing, Michael J. Fox, and Sharon Stone.
Although Fowler provided redacted screenshots depicting parts of the unsecured databases, a spokesperson for the Tribeca Film Festival told Cybernews on Monday that "none of the talent referenced in recent reporting had personal contact information disclosed.”
"All information was removed promptly upon discovery," they added.
“The vast majority of the information consisted of public-facing business contact information, including PR representatives, talent representatives, front office email addresses, information from the Festival website, and other information that was already publicly available,"the Tribeca Film Festival representative said.
Muhammad Yahya Patel, CISO and cybersecurity advisor at Huntress, said the leak is a reminder that even Hollywood can't escape a misconfigured database.
“The Tribeca Film Festival breach is a reminder that the most glamorous names in the world are only as secure as the least glamorous part of their digital footprint.”
“No sophisticated attack, no nation-state actor, no zero-day exploit. Just a misconfiguration that anyone with a browser and basic knowledge could have stumbled across,” Patel explained.
Patel also noted that even though compromised information may seem relatively benign, direct contact details for high-profile celebrities are worth serious money to tabloids, stalkers, and social engineers alike.
“Combined with device information, it’s also a useful reconnaissance package for targeted phishing attempts against people whose personal and financial lives make them attractive marks,” he said.
A leak inside one of Hollywood's biggest festivals
The Tribeca Film Festival is one of the world's largest film festivals, bringing together thousands of filmmakers, celebrities, and entertainment industry professionals in New York City each year.
Celebrating its 25th anniversary this June, the Festival draws anywhere between 130,000 and 150,000 attendees each year.
About 13,000 high-profile individuals and industry contacts are registered for the festival, according to Variety, with big names varying each year depending on what films are being shown or promoted.
Fowler said while some contact fields contained personally identifiable information(PII), he also admitted that others “were blank or missing data, or contained the contacts of assistants or management that could be publicly available."
Still, the security researcher pointed out that whether Hollywood A-lister or non-celebrity attendees,
“Hypothetically, publicly exposed internal data could provide criminals with a detailed view of non-public festival operations, potentially including information about participants, filmmakers, media assets, communications, and much more.”
Fowler warned that bad actors gaining access to such information, as with all data leaks, could lead to “targeted phishing, social engineering, identity correlation, impersonation attempts, or further reconnaissance of internal storage systems.”
Databases were publicly accessible
Fowler said after uncovering the first database, he found an additional “three separate unsecured databases,” as well as a fourth database that was properly secured. The databases and the number of records associated with each included:
- Development: 203,370 records
- Staging: 224,999 records)
- Production: 238,000 records
- Content Management System (CMS)
The exposed information reportedly included names, email addresses, phone numbers, mailing addresses, and internal festival communications, with the majority of records including images, press kits, marketing materials, and documents, some marked confidential.
However, he further reported that while examining the production database, he discovered “a single backup .dump file that contained potentially sensitive information, including
- Email addresses,
- Phone numbers,
- IP addresses,
- Hashed passwords.”
Patel reminds defenders that data breaches don’t always require a sophisticated attacker.
The CISO argues that regular external exposure assessments, proper access controls on databases containing sensitive contacts, and basic configuration hygiene would have prevented the exposure entirely.
“It’s not exciting security work, but it’s exactly the kind of unglamorous practice that protects even the most famous names in the world from becoming a headline," he said.
Check if your data has been leaked