A major data exposure has reportedly affected systems linked to the Tribeca Film Festival after cybersecurity researcher Jeremiah Fowler discovered multiple publicly accessible databases containing hundreds of thousands of records.
The databases were not protected with passwords or encryption, potentially exposing sensitive festival data dating from 2019 through 2026.
According to Fowler, the exposed databases were labeled “development,” “staging,” and “production,” and together contained more than 666,000 records. While investigating the data, he also found references to a separate content management system database that remained properly secured. The publicly accessible databases reportedly included press kits, marketing materials, images, internal documents, and some files marked as confidential.
The most sensitive discovery was a backup file stored in the production database. The file reportedly contained nearly 296,000 records with email addresses, phone numbers, IP addresses, and password hashes. It also included folders related to users, film contacts, and other internal records, suggesting the backup contained a broad snapshot of operational data.
After verifying the exposure, Fowler contacted multiple Tribeca Film Festival representatives through a responsible disclosure process. The backup file was removed or restricted on the same day, and the organization later confirmed it was investigating the issue while thanking the researcher for reporting it responsibly.
It remains unclear whether the exposed databases were managed directly by the Tribeca Film Festival, Tribeca Enterprises, or an external contractor or service provider. There is also no evidence showing how long the databases were publicly accessible or whether unauthorized individuals accessed the information before it was secured.
During his limited review, Fowler observed contact information linked to filmmakers, producers, and actors. The records reportedly included names matching well-known figures in the entertainment industry, although he emphasized that some entries may have belonged to assistants, management teams, people with identical names, or publicly available contacts. He also stressed that he found no evidence suggesting these individuals were specifically targeted or harmed.
The exposed records included fields containing user IDs, email addresses, names, newsletter preferences, sign-in history, IP addresses, and password hashes generated using the Bcrypt hashing algorithm. Fowler noted that Bcrypt is considered a secure method for storing passwords because it is a one-way hashing process rather than reversible encryption.
The researcher warned that exposed internal databases can provide valuable intelligence for cybercriminals, potentially enabling phishing campaigns, impersonation attempts, and social engineering attacks. Even if passwords remain securely hashed, personal contact details and operational information could still be misused to create convincing fraudulent communications.
Fowler also highlighted that backup files often receive less security attention than production systems despite frequently containing complete copies of sensitive data. He recommended encrypting backups, restricting access with authentication controls, and continuously monitoring storage environments for unauthorized exposure.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
The report referenced growing concerns about celebrity impersonation scams, noting that scammers increasingly use publicly available personal information to gain victims’ trust. Fowler added that advances in AI-generated deepfakes may further increase the effectiveness of these schemes in the future.









