Angelina Jolie once moved her family across continents to avoid the paparazzi. Robert De Niro co-created an entire institution to revitalize the neighborhood he loved. Both reportedly had their private contact details sitting in an unsecured database that anyone with an internet connection could have stumbled across. Their information, along with the details of dozens of other Hollywood heavyweights, was allegedly exposed in what a cybersecurity researcher is calling the largest celebrity data leak he has ever encountered.
The breach did not come from a sophisticated hack or a rogue insider at a talent agency. It came from a database that was simply left open. No password. No protection. Just hundreds of thousands of records sitting there, accessible to anyone who found them, labeled simply “Contacts.”
What Actually Happened

Jeremiah Fowler, an independent cybersecurity researcher and co-founder of Security Discovery, discovered four publicly accessible databases containing roughly 666,000 records dated from 2019 through 2026. Most were marketing files, but one allegedly included celebrities’ private email addresses and mobile phone numbers.
Fowler discovered the leak in a database named “contacts,” which was accidentally made public online days before the Tribeca Film Festival started on June 3. He received an email on June 4 from a legal executive at the festival’s parent company, Tribeca Enterprises, who said they were actively investigating the issue.
The festival responded that it takes matters of data security seriously and had since removed the databases. It is not clear how long the information was publicly available online or who accessed it.
The Scale of It

Fowler described what he found as “by far the biggest collection of celebrity data I’ve ever seen,” with private phone numbers and email addresses of a host of big-name celebrities made publicly accessible online.
Among those reportedly affected were Angelina Jolie, Robert De Niro, Jennifer Lawrence, Morgan Freeman, Winona Ryder, Martin Scorsese, George Lucas, Danny Boyle, Rami Malek, Sharon Stone, Neil Patrick Harris, and Michael Douglas.
Fowler himself noted: “It’s really unique because these individuals are so guarded and they protect their personal privacy, their contacts, their phone numbers.” A single unlocked database erased all of that effort for potentially thousands of entries at once.
Sources told The Cyber Express that the vast majority of the contact details leaked were actually for the talents’ agents and managers, rather than the celebrities’ personal details. That distinction slightly softens the picture for the celebrities themselves, while simultaneously representing a serious security exposure for the professional networks built to protect them.
The Festival at the Center of It

Jane Rosenthal and De Niro founded the Tribeca Film Festival in the aftermath of the September 11 attacks to revive lower Manhattan through the healing power of film and storytelling. Rosenthal and Robert De Niro had established Tribeca Productions and the Tribeca Film Center together back in 1989. The festival, which in 2026 marked its 25th anniversary, has grown into one of New York’s most prominent cultural events.
The festival hosts over 600 screenings annually and welcomes approximately 150,000 attendees. Gathering that many people – celebrities, executives, journalists, publicists, agents, managers, sponsors – means gathering a vast amount of personal data. Every accreditation, every guest list, every speaker inquiry produces a new data point. Over years of operation, that volume compounds quickly.
The four breached databases allegedly contained around 666,000 records from 2019 to 2026 relating to the annual movie festival in New York. That seven-year window reflects how data accumulates when an organization grows faster than its data governance practices do.
Why Contact Details Are More Dangerous Than They Sound

While there is no indication that passwords, financial information, or government identification documents were exposed, cybersecurity experts warn that contact details associated with public figures can still create significant security risks. Criminals frequently use leaked contact information to conduct phishing campaigns, impersonation scams, and social engineering attacks designed to obtain additional personal or financial information.
Fowler put it plainly: “There were many, many household names in the records who could have been targeted with malware.” When the person receiving a fraudulent message is Jennifer Lawrence’s agent or Martin Scorsese’s manager – someone whose job it is to act quickly on correspondence from people they know – the potential for a successful social engineering attack goes up considerably.
Film festivals, award ceremonies, and industry conferences routinely gather large amounts of data from celebrities, journalists, executives, and guests. Security specialists argue that organizations handling such information should conduct regular audits and maintain stronger safeguards to prevent accidental exposure.
What Happens After a Database Gets Secured

Once Fowler flagged the issue, the databases were taken down. The discovery prompted questions about how the information was stored and whether unauthorized individuals may have accessed the database before it was secured. Taking a database offline removes the exposure going forward. It does nothing about the window between when the data became accessible and when someone realized it shouldn’t be.
Fowler also noted: “What was really interesting was that there was a folder that captured their device information based off the email.” Device data gleaned from email opens is a standard marketing analytics tool, used by organizations of all sizes to track engagement. In the context of a breached database, it becomes one more layer of information attached to a celebrity’s identity that was sitting unsecured in the open.
The Tribeca Festival’s parent company, Tribeca Enterprises, responded to the notification. The exposed databases were then removed from public access, though it’s not clear how long they were online. Representatives for the major celebrities named have been approached for comment; as of this writing, no public statements have been issued by the affected parties.
The Bigger Picture for Anyone Who’s Ever Been on a Guest List

The incident has renewed attention on how entertainment organizations collect, store, and secure personal information. Every event you attend, every conference you register for, every festival you apply to screen at – your information goes somewhere. Usually into a database managed by whoever ran the event, governed by whatever data security practices they happened to have in place that year. Sometimes those practices are robust. Sometimes the folder is just called “Contacts” and it’s open to the internet.
The celebrity angle makes the story, but the structural failure is one that applies to anyone whose contact details have ever been collected by an organization that didn’t quite understand what it was holding.
The Part Nobody Can Fix After the Fact

Once data has been sitting in an accessible location for an unknown amount of time, the real question isn’t whether it’s been seen. The question is what was done with it, and whether anyone will know if the answer is anything other than “nothing.”
The Tribeca Film Festival responded quickly once Fowler made contact. But the speed of the response only addresses the ongoing exposure, not the historical one. The people whose details appeared in that database have no way of knowing who else found it first. That’s the part that doesn’t resolve cleanly, regardless of how fast the databases come down.
The databases are offline. The investigation is ongoing. But the data that was in them, for however long it was accessible, has already been whatever it was going to be. There is no recall.
Disclaimer: This information is not intended to be a substitute for professional medical advice, diagnosis, or treatment and is for information only. Always seek the advice of your physician or another qualified health provider with any questions about your medical condition and/or current medication. Do not disregard professional medical advice or delay seeking advice or treatment because of something you have read here.
AI Disclaimer: This article was created with the assistance of AI tools and reviewed by a human editor.