How to Contact your Favorite Celebrity

31214613470?profile=RESIZE_180x180Contact details of Angelina Jolie, Robert De Niro and Martin Scorsese have been exposed in a data breach.  Jennifer Lawrence, Morgan Freeman, Michael Douglas, Rami Malek, Sharon Stone, and directors George Lucas and Danny Boyle are also said to have been involved in the alleged leak last month.  The stars’ phone numbers and email addresses were revealed after a Tribeca Film Festival database, simply named “contacts”, was accidentally made public online, with Jeremiah Fowler, a researcher for Black Hills Information Security, claiming he discovered the document days before the festival started on 3 June.[1]

Fowler came across the database while examining online resources. It contained a list of contacts that should have remained private. The accidental public availability meant that anyone who found the link could access the information. This happened just before the festival opened its doors to attendees and participants. The Tribeca Film Festival is an annual event that attracts numerous figures from the entertainment world. Maintaining secure contact records is essential for such occasions, yet the open nature of this file led to the current situation.

Phone numbers and email addresses of famous people hold value in certain circles. They can be used by those seeking to contact individuals directly without going through official channels. Device information adds to the package by providing insights that could support more focused attempts to gain further access or information. For people in the public eye, such exposures can lead to increased unwanted communication and potential security concerns for their personal lives.

In an expert comment, Muhammad Yahya Patel, vCISO & Cybersecurity advisor at Huntress, said, "Even A-listers can’t escape a misconfigured database.  The Tribeca Film Festival breach is a reminder that the most glamorous names in the world are only as secure as the least glamorous part of their digital footprint in this case, a database called 'contacts' that was simply left open on the internet. No sophisticated attack, no nation-state actor, no zero-day exploit. Just a misconfiguration that anyone with a browser and basic knowledge could have stumbled across.

The data exposed phone numbers, email addresses, and device information; it might seem relatively benign. For high-profile individuals, it’s anything but. Direct contact details for celebrities of this profile are worth serious money to tabloids, stalkers, and social engineers alike. Combined with device information, it’s also a useful reconnaissance package for targeted phishing attempts against people whose personal and financial lives make them attractive marks."

The broader point is one thing the industry keeps having to restate: data breaches don’t always require a sophisticated attacker. Sometimes the door is just left open. "Regular external exposure assessments, proper access controls on databases containing sensitive contacts, and basic configuration hygiene would have prevented this entirely. It’s not exciting security work, but it’s exactly the kind of unglamorous practice that protects even the most famous names in the world from becoming a headline." Patel concludes.

 

This article is shared at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC).  For questions, comments or assistance, please contact the office directly at 1-844-492-7225, or feedback@redskyalliance.com    

Weekly Cyber Intelligence Briefings:
REDSHORTS - Weekly Cyber Intelligence Briefings
https://attendee.gotowebinar.com/register/7855487668891299929

 

[1] https://www.cybersecurityintelligence.com/blog/hollywood-stars-exposed-in-festival-database-breach-9580.html

E-mail me when people leave their comments –

You need to be a member of Red Sky Alliance to add comments!