Particle.news

Large Tribeca Cloud Exposure Found That Included a Contacts Backup

The discovery raises risks of targeted phishing, prompting Tribeca to remove the files for an ongoing investigation.

Overview

  • Security researcher Jeremiah Fowler found multiple publicly accessible Tribeca-related cloud databases days before the festival began on June 3, and he reported the issue to organisers who removed the files.
  • Fowler and several outlets say the caches total about 666,369 records from 2019–2026 and included a backup .dump with a ‘contacts’ folder that held roughly 13,535 entries.
  • The festival says most records were public-facing business contacts such as PR and talent-rep emails and that no talent personal contact information was disclosed, and Tribeca confirmed it opened an investigation.
  • Fowler attributes the exposure to human error: an unencrypted backup left in a production-accessible cloud location rather than an active hack, and he says some entries contained assistants’ or managers’ contacts rather than direct personal details.
  • It remains unknown how long the files were public or whether anyone accessed them maliciously, and experts warn exposed contact data can enable targeted phishing, malware delivery, and AI-powered social engineering.