A reported Tribeca data leak exposed names, phone numbers, email addresses and device information linked to some of Hollywood’s best-known figures, including Angelina Jolie and Robert De Niro. But the central risk may extend beyond celebrities themselves: agents, managers and other industry contacts can be valuable targets for criminals trying to make a fraudulent message look convincingly routine.
Cybersecurity researcher Jeremiah Fowler said he discovered 666,369 files covering Tribeca activity from 2019 through 2026. The material was publicly accessible online because of what he described as human error, rather than a deliberate release.
There is no confirmed evidence that the information was misused. Fowler also found no ransomware demand or other visible sign of criminal exploitation. That does not prove nobody accessed the files while they were exposed, which is the less comforting part of how public databases work.
What information was reportedly exposed?
The records allegedly included names, phone numbers and private email addresses. Financial Express also reported that some files contained device details, including whether a person used an iPhone, along with browser and software versions.
That combination can be useful to attackers. Contact details may support impersonation attempts, while device information can help criminals tailor malware or identify people using outdated software.
Fowler told The Sun that the collection was “by far the biggest collection of celebrity data” he had encountered. He said prominent people listed in the records could have been targeted with malware.
Reportedly affected names included:
- Angelina Jolie
- Robert De Niro
- Martin Scorsese
- George Lucas
- Morgan Freeman
- Jennifer Lawrence
- Winona Ryder
- Neil Patrick Harris
- Rami Malek
- Sharon Stone
- Michael Douglas
- Danny Boyle
Being named in the collection does not establish that each celebrity’s personal phone number or private inbox was exposed. A source told The Sun that the “vast majority” of contact details belonged to managers and agents. Fowler, however, said the presence of Gmail and Yahoo addresses suggested at least some information could have been personal.
Why agents and managers may be the real target
The distinction between a celebrity’s number and a representative’s contact details matters, but it does not remove the danger. Hollywood business runs through assistants, managers, agents, lawyers and production staff, often under tight deadlines and with large payments or sensitive documents involved.
A criminal with access to names, roles and authentic contact information could impersonate a public figure or trusted colleague. That may enable business-email-compromise schemes, malware delivery or requests for confidential material. The approach does not require compromising Angelina Jolie’s own phone if an attacker can instead send a persuasive message to someone who handles her work.
Fowler said the exposure was unusual because high-profile people closely guard their contact networks. The records may therefore reveal not only individual details but part of the professional infrastructure surrounding major actors and filmmakers.
The seven-year span also raises questions about data retention. It remains unclear why information dating back to 2019 was stored together, how long it was accessible from the internet or how many unique people appeared in the collection.
How did Tribeca respond?
Fowler reportedly alerted Tribeca shortly before its 12-day festival began in New York on June 3, 2026. The exposed material was subsequently removed from public access.
On June 4, Fowler received an email from a legal executive at Tribeca Enterprises saying the organization was “actively investigating this issue.” He said the quick response indicated that officials recognized the material and understood it should not have been publicly available.
Reports differ on the number of exposed databases. Metro cited three, while Financial Express, referring to reporting by The Telegraph, said there were four. Tribeca has not publicly clarified that discrepancy, and the precise configuration error has not been disclosed.
There is no suggestion that Tribeca intentionally released the information. No further public statement from the organization or the named celebrities had been reported by July 27.
The absence of confirmed abuse is important, but so is the broader lesson. Entertainment events collect years of contact and technical information from guests, representatives and staff. When all of it remains accessible in one place, even a simple configuration mistake can turn a festival database into a detailed map of an industry built on guarded access.



