Particle.news
Download on the App Store

Tribeca Data Leak Exposed About 666,000 Files Including 13,500 ‘Contacts’ Entries

Found and reported by researcher Jeremiah Fowler, the unsecured backup raises alarm that unencrypted contact metadata can enable highly targeted AI-driven phishing.

Overview

  • A cybersecurity researcher discovered roughly 666,369 publicly accessible files tied to the Tribeca Film Festival that dated from 2019 through 2026 and reported the exposure to organizers days before the June festival began, after which the files were removed from public access.
  • One backup .dump included a folder labeled “contacts” with about 13,535 entries that contained names, email addresses, phone numbers and some postal addresses, though some records appeared to list agents, publicists or incomplete fields rather than personal details.
  • Tribeca says the bulk of the material was public-facing business information and that no talent personal contact details were disclosed, and the festival has opened an investigation into how the files became accessible.
  • The researcher and multiple reports say the exposure resulted from human error: an unencrypted backup left in a production cloud environment that could be indexed and viewed through internet-connected‑device search tools.
  • Security experts warn the leak matters beyond privacy because unencrypted contact and device metadata can be combined with off‑the‑shelf AI to craft convincing, targeted phishing and social‑engineering attacks, so observers will watch Tribeca’s remediation and any signs of misuse closely.