Logo

Massive Tribeca Fest Data Leak Exposes Jennifer Lawrence, Robert De Niro and More Celebs’ Contact Info; Meet the Man Who Discovered the Files

Movies & TV
Massive Tribeca Fest Data Leak Exposes Jennifer Lawrence, Robert De Niro and More Celebs’ Contact Info; Meet the Man Who Discovered the Files
The Tribeca Festival suffered a data leak that exposed hundreds of thousands of records, as well as the contact information for thousands of celebrities, including Martin Scorsese, Francis Ford Coppola, Jennifer Lawrence, Angelina Jolie and festival co-founder Robert De Niro.
Cybersecurity researcher Jeremiah Fowler revealed the leak in an ExpressVPN blog post over the weekend, claiming he’d uncovered a total of 666,369 exposed records with timestamps ranging from 2019 to 2026. Fowler, who works for Black Hills Information Security, publishes blogs on ExpressVPN and previously did cybersecurity for a software company in Kyiv, Ukraine, took time away from his European vacation to speak with Variety about discovering the data leak.

“I’ve been a security researcher for about 15 years and I’m always looking for exposed data,” he says. “I’ve used a lot of different APIs and tools. This one I found using an IoT search engine, which is basically Google for websites but for connected devices like nanny cams, medical equipment or cloud storage databases.”

Co-founded in 2002 by De Niro, Jane Rosenthal and Craig Hatkoff as a way to revitalize Lower Manhattan following the September 11 attacks, the fest takes place annually in New York City, and has played host to the premieres of everything from “The Avengers” to “The Handmaid’s Tale,” while awarding films like “Let the Right One In.” Tribeca Festival’s 2026 edition, marking its 25th anniversary, ran from June 3-14.
The festival issued a statement, with a spokesperson asserting, “None of the talent referenced in recent reporting had personal contact information disclosed. The vast majority of the information consisted of public-facing business contact information, including PR representatives, talent representatives, front office email addresses, information from the Festival website, and other information that was already publicly available. All information was removed promptly upon discovery.”While the majority of the Tribeca Festival data was not sensitive, consisting of things like marketing materials, press kits and promotional images, there was a backup .dump file that “contained potentially sensitive information,” including a folder named “contacts” that had 13,535 entries, including “the names, addresses, phone numbers and emails” of prominent filmmakers like Scorsese, Coppola, Guillermo del Toro, Ron Howard, and others, as well as popular actors such as De Niro, Lawrence, Jolie, Morgan Freeman, Rami Malek, Eva Mendes and Michael J. Fox. Fowler noted, however, that some of the contact fields were missing data or contained the contacts of assistants, managers or publicists in lieu of a personal email or phone number. (Variety is still awaiting comment from the Tribeca Festival, which disputed some of Fowler’s findings by phone.)

“Normally, when you back up something, you don’t keep it in a production environment,” he says of Tribeca’s folly. “You either take it offline or put it in a separate database, that way it’s your fail-safe in case something does go wrong. One document had around 135,000 contacts, and I’m assuming these would be people who signed up for mailing lists and people that go to events. The celebrities were in something called ‘contacts,’ and that had around 13,000.”
He adds, “[Tribeca] kind of disputed that some — not all — of the contacts may have been managers or assistants, but I saw a lot of consumer email accounts, like Google or Yahoo.”
According to Fowler, the Tribeca Festival committed “a human error of leaving the backup file in the database, and the backup file was in plain text, unencrypted.” If it was encrypted, he wouldn’t have been able to access it. But every one of the data points, he explains, was available to anyone with an internet connection, so anyone could create an account with a IoT search engine and view the data in a browser like Chrome, Firefox or Safari.
While the Tribeca Festival made a mistake in leaving the data exposed, Fowler commended the actions the fest took in the wake of his revelations, admitting the fest “responded very fast and professionally.” Plus, he “didn’t see any evidence of anyone else accessing it,” since normally data that’s been exposed for a lengthy period of time would come with automatic ransomware posts requesting various amounts of bitcoin, and those weren’t there.
He warns that exposing people’s personal data, such as email accounts, poses an even bigger threat in the era of AI, which has democratized hacking.

“The creativity level of criminals has shot up beyond anything. AI gives anyone the ability to do things that non-technical people couldn’t do before,” he reasons. “Now, you can feed it information and ask it to create a phishing email. You could use Claude, ask it to create malware, insert it in a document saying, ‘Check out this script!’ and send it to 135,000 people, and somebody’s going to open it. It’s a very, very big issue.”
As a seasoned cybersecurity researcher, Fowler maintains that his mission isn’t to embarrass companies, but rather show them where their vulnerabilities lie and get them to improve their cybersecurity so that their information doesn’t fall into the wrong hands in the future.
“The purpose of my report and findings are not to throw organizations under the bus,” he says. “Organizations that do have a data incident statistically don’t have another one for three to five years since it becomes a primary focus and you dedicate the resources to penetration testing and vulnerability scans. It happens often, especially in industries unrelated to technology.”

Riff on It

Riffs (0)