THE "CONTACTS" FOLDER THAT CONTAINED HOLLYWOOD'S MOST GUARDED SECRETS — AND THE FESTIVAL THAT LEFT THE DOOR WIDE OPEN

THE "CONTACTS" FOLDER THAT CONTAINED HOLLYWOOD'S MOST GUARDED SECRETS — AND THE FESTIVAL THAT LEFT THE DOOR WIDE OPEN
The Tribeca Film Festival is not some scrappy indie operation running on a shoestring budget. Co-founded in 2002 by Robert De Niro, producer Jane Rosenthal, and investor Craig Hatkoff, it has grown into one of the most influential film festivals in the world — a twelve-day celebration of cinema held every June in lower Manhattan.
To attend Tribeca at any meaningful level — as a presenter, a VIP guest, a press credential holder, a sponsor — you hand over personal information. Your name. Your email. Your phone number. The kind of data that, in any responsible organization, gets stored behind multiple layers of security.
At Tribeca, according to Fowler's findings, it got stored in an unsecured cloud database that anyone on the internet could access. No password. No encryption. Nothing.
Fowler, a researcher at Black Hills Information Security, discovered the exposed database in the days before the 2026 festival opened on June 3. He found three separate databases containing a combined 666,369 records — an unsettling number that cybersecurity forums immediately noticed.
Most of those records were marketing materials — press releases, event schedules, promotional content. Standard festival operations. Nothing scandalous.
But buried among the marketing files, Fowler found something else entirely: a backup folder labeled simply "Contacts."
Inside were approximately 200,000 records tied to real people — actors, directors, producers, media members, festival staff. And those records didn't just contain names and job titles. They contained phone numbers. Private email addresses. And device details — the specific make and model of the person's phone, down to the iPhone version and software build.
That last detail is what has cybersecurity experts most alarmed.
A phone number alone is dangerous. A private email address alone is dangerous. But a phone number combined with a private email combined with the exact device model creates what security researchers call a "social engineering starter kit" — everything a sophisticated attacker needs to craft a convincing phishing message or exploit a known vulnerability specific to that device.
According to FTC data, impersonation fraud losses in America ballooned from $55 million in 2020 to $445 million in 2024 — a nearly 800 percent increase in four years. A leaked celebrity phone number isn't trivia. It's raw material for the fastest-growing category of financial crime in the country.
Fowler immediately notified Tribeca Enterprises. The databases were secured the following day. But "secured the next day" means nothing if the data was exposed for years before anyone noticed.
And the records Fowler found were timestamped from 2019 to 2026 — suggesting the exposure window could have been as long as seven years.
Seven years. Think about how many phones you've replaced since 2019. How many passwords you've updated. Now imagine you're Morgan Freeman, and your personal phone number has been on a public server since before COVID — and nobody told you.
May you like
The full list of affected celebrities reads like the guest list at the most exclusive party on earth. And what connects all of them is a single organization that treated their most sensitive information with all the security of a Post-it note stuck to a refrigerator.
👉 CONTINUE READING — PAGE 3
