Tribeca Festival suffered a data breach that exposed hundreds of thousands of records and contact information for thousands of celebrities, including Martin Scorsese, Francis Ford Coppola, Jennifer Lawrence, Angelina Jolie and festival co-founder Robert De Niro.
Cybersecurity researcher Jeremiah Fowler revealed the breach in an ExpressVPN blog post over the weekend, claiming to have discovered a total of 666,369 exposure records with timestamps from 2019 to 2026. Fowler, who works for Black Hills Information Security and blogs on ExpressVPN and previously worked in cybersecurity for a software company in Kiev, Ukraine, spoke to Variety about the discovery while on vacation in Europe. Data leak.
“I’ve been working as a security researcher for about 15 years, and I’m always looking for publicly available data,” he says. “I’ve been using a lot of different APIs and tools, which I found using the IoT search engine. It’s basically Google for websites, but for connected devices like nanny cameras, medical equipment, and cloud storage databases.”
Co-founded in 2002 by De Niro, Jane Rosenthal and Craig Hutkoff as a way to revitalize Lower Manhattan after the September 11 attacks, the festival, held annually in New York City, has hosted premieres of everything from The Avengers to The Handmaid’s Tale and honored films such as Let the Right One In. The 2026 edition of Tribeca Festival, celebrating its 25th anniversary, was held from June 3rd to 14th.
The festival issued a statement, with a spokesperson claiming, “None of the talents mentioned in recent reports had their personal contact information disclosed. The majority of the information consisted of publicly available business contact information, including publicists, talent representatives, front office email addresses, information from the festival’s website, and other information that was already publicly available. All information was promptly deleted upon discovery.”
While most of the Tribeca Festival data was not sensitive, consisting of marketing materials, press kits, promotional images, etc., there were backup .dump files that “contained potentially sensitive information.” Among them was a folder called “Contacts” that contained 13,535 entries including “names, addresses, phone numbers, and emails” of famous filmmakers and popular actors such as Scorsese, Coppola, Guillermo del Toro, and Ron Howard. De Niro, Lawrence, Jolie, Morgan Freeman, Rami Malek, Eva Mendes, Michael J. Fox, and more. However, Fowler noted that some of the contact fields were missing data or contained contact information for assistants, managers, and publicists instead of personal emails and phone numbers. (Variety is awaiting comment from the Tribeca Festival, which disputed some of Fowler’s findings over the phone.)

A screenshot of a portion of the data breach where sensitive information was redacted.
Jermaine Fowler
“Typically when you back something up, you don’t save it in production,” he says of Tribeca’s foibles. “Either take it offline or store it in a separate database. That way you have a failsafe in case something goes wrong. One document had about 135,000 contacts, and I think these were people who signed up for mailing lists and people who went to events. Celebrities were in so-called ‘contacts,’ and they had about 13,000 contacts.”
He added: “[Tribeca]took some issue with the fact that some (but not all) of the contacts may have been managers or assistants, but confirmed that there were a number of consumer email accounts such as Google and Yahoo.”
Fowler said Tribeca Festival “made a human error in leaving a backup file in the database, and the backup file was unencrypted and in plain text.” If it was encrypted, he wouldn’t have been able to access it. But all data points are available to anyone with an internet connection, he explains, so anyone can create an account on the IoT search engine and view the data in a browser like Chrome, Firefox or Safari.
Although Tribeca Festival made the mistake of leaving the data public, Fowler praised the festival’s actions in response to his revelations, acknowledging that the festival “responded very quickly and professionally.” Additionally, data exposed over a long period of time is typically accompanied by automated ransomware posts demanding various amounts of Bitcoin, but since these did not exist, “we saw no evidence that anyone else had access to it.”
He warns that in the age of AI, where hacking has been democratized, exposing personal data such as email accounts poses an even greater threat.
“The level of creativity among criminals is at an all-time high. Thanks to AI, anyone can do things that non-technical people couldn’t do before,” he reasons. “You can now enter your information and request that a phishing email be created. You can also use Claude to request that malware be created and insert ‘Check this script!’ into your document.” If you send it to 135,000 people, someone will open it. That’s a very, very big problem.”
Fowler, an experienced cybersecurity researcher, insists his mission is not to embarrass companies, but to show them where their vulnerabilities lie and help them improve their cybersecurity to prevent information from falling into the wrong hands in the future.
“The purpose of my report and findings is not to bring organizations down,” he says. “Statistically, organizations that experience a data incident do not experience another data incident for three to five years because the data incident becomes their primary focus and they devote resources to penetration testing and vulnerability scanning. This happens often, especially in non-technology industries.”
