THE NAMES. THE RISKS. AND WHAT THIS MEANS FOR EVERY PERSON WITH A PHONE NUMBER.

THE NAMES. THE RISKS. AND WHAT THIS MEANS FOR EVERY PERSON WITH A PHONE NUMBER.
Here is a partial list of the people whose private contact information was reportedly exposed, according to Fowler's published findings and reporting by CyberNews, IBTimes, PJ Media, and multiple other outlets:
Angelina Jolie. Robert De Niro. Morgan Freeman. Jennifer Lawrence. Martin Scorsese. George Lucas. Ron Howard. Sharon Stone. Michael Douglas. Rami Malek. Neil Patrick Harris. Hilary Duff. Winona Ryder. Danny Boyle.
Those are the names Fowler specifically identified. But the full "Contacts" folder contained approximately 200,000 individual records — meaning the names above are a fraction of the total exposure.
Talent agents. Studio executives. Entertainment lawyers. Publicists. Journalists. Festival volunteers. Hotel concierges. Car service drivers. Anyone who entered the Tribeca ecosystem between 2019 and 2026 and provided personal contact information may have had that data sitting on the open internet for up to seven years.
Tribeca Enterprises has not issued a detailed public statement beyond confirming to Fowler that the databases were secured after his notification. The organization has not publicly disclosed whether it has notified affected individuals.
That silence is itself a significant legal concern.
Under New York's SHIELD Act — the Stop Hacks and Improve Electronic Data Security Act — any company that owns computerized data containing private information of New York residents is required to notify affected individuals "in the most expedient time possible" following a breach. California has its own even stricter requirements under the CCPA.
Whether Tribeca has complied — whether Angelina Jolie knows her phone number was exposed, whether Morgan Freeman knows his email was on a public server — is a question nobody has answered.
And here's why this isn't just a celebrity story. It's your story, wearing a designer dress.
Every company you've ever given your phone number to stores that data on a server somewhere. Every festival. Every ticket platform. Every hotel loyalty program. Every restaurant reservation app. Every medical office check-in tablet. Every school enrollment form.
The security protecting that server is only as strong as the weakest decision made by the least careful person with access to it.
If the Tribeca Film Festival — backed by De Niro, backed by major corporate sponsors, operating in one of the most legally regulated cities in the country — can leave Angelina Jolie's phone number on an unprotected server for seven years without noticing, what do you think is happening with your data at the dentist's office? At the gym? At the grocery store loyalty program where you scan your card every Tuesday?
The cybersecurity industry has a technical term for this kind of failure. They call it a "misconfigured cloud storage" incident.
Translation: someone forgot to click the "require password" box when they set up the database.
That's it. That's the entire security failure. A checkbox. A single setting. The digital equivalent of forgetting to lock the front door — except the front door protects the personal information of some of the most targeted human beings on the planet.
Fowler followed responsible disclosure protocols. He found the exposure. He notified Tribeca. The databases were secured. He published his findings. That's how the system is supposed to work.
But Fowler was looking for exposed databases as part of his professional research. He found this one because he was specifically searching for exactly this kind of misconfiguration.
The question nobody can answer is whether anyone else found it first.
And if they did? If someone with criminal intent discovered 200,000 records before Fowler raised the alarm?
The damage wouldn't look like a dramatic hack or a splashy ransom demand. It would look like a phone call from someone who sounds exactly like your agent. An email that looks exactly like it came from the festival organizer. A text message referencing a real event you actually attended, from a number that looks like it belongs to someone you actually know.
That's how modern impersonation fraud works. Not with crude Nigerian prince emails. With precisely targeted messages built from precisely the kind of personal data that was sitting on Tribeca's cloud server for up to seven years.
666,369 total records. 200,000 individual contacts. Phone numbers. Private emails. Device models. Names that fill marquees from Hollywood to Cannes.
And the only reason the world knows about any of it is because one researcher happened to be looking in the right place at the right time.
May you like
Your data is sitting on a server somewhere too. Probably more than one. Probably at companies far less sophisticated than the Tribeca Film Festival.
Feel safe?
