
The researcher who uncovered a huge alleged celebrity data breach surrounding the Tribeca Film Festival has said the leaked details could have been a goldmine for hackers.
Jeremiah Fowler is a cybersecurity expert of 15 years and uncovered a reported leak which exposed several Hollywood stars' personal contact information, allegedly including Angelina Jolie.
The leak stemmed from databases related to this year's Tribeca Film Festival, founded by Robert De Niro in 2002, which were exposed, leading Fowler to find 666,369 files.
Outlining his findings in his blog, most of the files contained non-sensitive information like press releases and cinema schedules. However, he says he also found thousands of email addresses and phone numbers in a back-up file.
Advert
What was even more concerning was that Fowler claims the devices the email addresses were used on were also collected.
This is a big risk as if the data was found by potential scammers, they would have enough convincing information to social engineer a scam with, which would allow them to contact family, friends and associates of the celebrities believably posing as them.
Fowler told LADbible: "From a cybersecurity standpoint, the craziest thing for me was that they were logging devices and correlating them with an email address.
"So, for example, I can correlate your email address, I see what phone you have, I see what operating system you have, what browser you're using, that would give a cyber criminal enough information, hypothetically, to further target that person."

Cybercriminals could have used the data to launch scams
Fowler says he saw several celebrities' information in the files, including actors Rami Malek, Sharon Stone, Neil Patrick Harris and Michael Douglas; directors Martin Scorsese, Danny Boyle and George Lucas, as well as Jolie and De Niro, plus many more.
A source told The Sun that the vast majority of the contact details leaked were actually for the talents' agents and managers, not personal details, though Fowler did see domains like Gmail and Yahoo, rather than business-specific emails, which would indicate otherwise.
He explained how criminals could have used that data in a scam to pose as a celebrity and spread malware to their contacts.
"I see the email address, I just change it by one letter and then I email all the people they may have contact with," he said.
"I'm like, 'hey, can you give me an update on this? Oh, check out this PDF file,' that just happens to have malware.
"The creativity of criminals now is 100-fold of what it was when I first started in this industry."
Fowler, an ethical researcher, immediately informed Tribeca Enterprises, which runs the festival, of the leak and he praised their 'great response.'
The exposed databases were immediately closed and the company thanked him for informing them of the vulnerability.
Fowler said: "They fixed it literally the same day. They acted really fast. They're a professional organisation. Data security might need some improvements..."

Cybersecurity expert's warning to businesses
It doesn't appear the information fell into the wrong hands, with Fowler speculating that if 'bad guys' did find the databases, they may have only seen the reams of non-sensitive files and not deemed them worth their time.
Whereas he looked for a back-up file, leading him to find a 'shiny gold coin hidden in the weeds' and the personal information.
Fowler says most data breaches of this kind stem from human error. In fact, his career in the industry started when the company he worked for at the time fell victim to a breach.
So he has sympathy, as well as clear advice for companies. Starting with those back-up files.
"The big thing here, is back-up files are probably the most dangerous files anybody could store," he said.
"It's smart to back up your system, but don't leave it with all your production data. Put it on a hard drive, put it on a separate database, get it away from your core data."
He also advised big companies to make sure they don't scrimp on cybersecurity, even if the investment doesn't make a financial return, as the losses can be devastating.
He added: "A lot of times, because of vulnerability scans, penetration testing, it's pretty expensive. A lot of times, these companies don't realise the data of your customers and users is equally, if not more, valuable than the products or services you provide.

"So you're doing a great disservice to yourself, your reputation, your brand and your customers by not implementing cybersecurity and vulnerability scans.
"Just be proactive."
On the Tribeca data, he added: "These were all stored in spreadsheets. You can encrypt spreadsheets. Not everybody in your organisation needs access to all this.
"If I saw this database and those files were encrypted, we wouldn't be talking right now.
"Even if it was completely open, tonnes of documents there, if they were encrypted, there's nothing I can do with it. Or the bad guys."
LADbible Group has approached the Tribeca Festival and the representatives of Angelina Jolie, Robert De Niro, George Lucas, Martin Scorsese, Sharon Stone, Rami Malek, Danny Boyle, Neil Patrick Harris, and Michael Douglas for comment.
Topics: Technology, Film, Angelina Jolie, Robert De Niro