in

Tribeca Cloud Leak Exposes 666,369 Records, A‑List Contacts at Risk

The Tribeca Film Festival was rocked by a fresh cybersecurity embarrassment this week when a researcher found hundreds of thousands of unsecured files tied to festival systems. Jeremiah Fowler says roughly 666,369 records were sitting in public cloud storage with names, email addresses, phone numbers and even device details for scores of industry figures. Tribeca removed the exposed databases after being notified and says it is investigating — but the messy questions about responsibility and damage are just starting.

What the leak contained

According to the researcher who found it, the exposed data included private email addresses, cell phone numbers and device metadata such as phone model, browser and software versions. That’s exactly the kind of detail a scammer uses to sound convincing in a phishing message. The list reportedly names A‑list talent, directors, producers and media professionals — people like Robert De Niro, Angelina Jolie, Martin Scorsese and others have been mentioned in press accounts. Whether those entries are personal contact info or professional agent contacts matters for privacy, and that distinction is not yet clear.

How this likely happened — and who should answer

Public cloud misconfigurations are boring to fix and expensive to ignore. The files appear to have been left accessible without password protection or encryption — the digital equivalent of leaving the office door wide open. It’s not proven whether Tribeca itself ran the exposed storage or if a vendor or backup system was at fault, but the festival still looks bad for not spotting this sooner. Accountability is simple: if you rely on outside vendors, check their doors; if you run the systems yourself, lock them down. Hollywood can afford consultants; security excuses won’t cut it.

Why this matters and what the exposed should do now

This isn’t just celebrity gossip. Contact lists and device details accelerate impersonation fraud, SIM swap attempts and targeted malware attacks. Impersonation losses in recent years have exploded, and a leaked phone number is raw material for crooks. Anyone named in the dataset should assume heightened risk: reset passwords, turn on two‑factor authentication, contact mobile carriers about SIM protections, and watch for suspicious texts and emails. Event organizers and vendors should also notify affected people promptly and offer monitoring or protection services.

Tribeca removed the data from public access after being alerted and says it is investigating, but the festival owes the public a clear account: who exactly was exposed, which systems failed, and whether outside forensic experts or law enforcement are involved. This episode is a reminder that elite status doesn’t buy immunity from sloppy security. Festivals, studios and their vendors need to stop treating basic cyber hygiene like an afterthought — and start acting like the data they hold matters. If they won’t, lawmakers and courts will make them care.

Written by Staff Reports

Watters: Fauci knew he BLEW IT

Senator Rand Paul drops Fauci diary ahead of subpoenaed hearing

Tiangong Tests Force Choice: Pioneers or Couch Potatoes

Tiangong Tests Force Choice: Pioneers or Couch Potatoes