Several unsecured databases linked to the Tribeca Film Festival exposed more than 666,000 records before they were secured, according to security researcher Jeremiah Fowler. The publicly accessible databases reportedly contained contact information and internal festival data collected over several years.
Fowler, of Black Hills Information Security, said he discovered four databases that were accessible without authentication shortly before the 2026 Tribeca Festival began in June. According to his findings, the databases contained a combined 666,369 records.
The first database, labelled “contacts,” reportedly held roughly 200,000 records associated with actors, directors, producers, media representatives, festival employees and other entertainment industry professionals. Fowler said he notified the organisation after identifying the exposed systems, and access was restricted the following day.
Because the databases required neither a password nor encryption, Fowler said it is impossible to determine how long they had been publicly accessible or whether anyone else accessed the information before it was secured.
The researcher reported that the records carried timestamps ranging from 2019 through 2026, suggesting the databases contained information accumulated over multiple festival editions. He also said it was unclear whether the exposed infrastructure belonged directly to the Tribeca Film Festival, its parent company, or an external service provider.
According to Fowler, some records referenced well-known actors, filmmakers, and other public figures. However, the presence of a celebrity’s name in a database does not necessarily indicate that the individual’s private contact information was exposed.
After the findings became public, a spokesperson for the Tribeca Film Festival disputed reports that celebrities’ personal contact details had been leaked. The organisation said none of the talent identified in media coverage had their personal contact information disclosed.
Tribeca also said the exposed information was removed immediately after being notified. According to the organisation, most of the records consisted of publicly available business contact details, including information for public relations firms, talent representatives, front-office email addresses and contact information already published through official festival resources.
Fowler acknowledged that the exposed data varied considerably between records. He said some entries contained personally identifiable information, while others were incomplete or listed assistants, management contacts or publicly available business representatives.
Beyond contact records, the researcher said the databases also contained images, press kits, marketing materials, documents and internal festival communications. Some files were reportedly marked as confidential.
While reviewing one of the production databases, Fowler also discovered a backup database dump that allegedly contained email addresses, phone numbers, IP addresses and hashed passwords. Hashing is a method of transforming passwords into cryptographic values so they are not stored in plain text, although hashed credentials may still present security risks depending on their implementation.
The researcher said the exposed information could potentially be useful in phishing, social engineering, or impersonation attempts if obtained by malicious actors. However, there is no evidence that the databases were accessed by unauthorized parties before they were secured.
The Tribeca Film Festival has not reported any confirmed misuse of the exposed information. The organisation maintains that the issue was addressed promptly after notification, while the full ownership of the exposed databases has not been publicly identified.
