[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxzp9ofjw8bl7":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":15,"source":16,"sourceUrl":17,"sourceUrls":18,"pwnCount":23,"affectedCount":23,"affectedCountStatus":24,"affectedCountLowerBound":13,"affectedCountUnit":25,"hasEnglishDescription":4,"contentLocale":26,"availableLocales":27,"translations":29,"severity":32,"dataClasses":33,"description":46,"seoTitle":47,"seoDescription":48,"logoUrl":49,"isVerified":4,"isSensitive":4,"isSpamList":50,"isMalware":50,"company":51},"6a46d386b71192447ece5f47","MyCastingFile","MyCastingFile (2020) Data Breach","mycastingfile-2020","mycastingfile.com","2020-05-31T00:00:00.000Z","2020-07-16T00:00:00.000Z",null,"2026-07-12T03:15:35.000Z","2026-07-19T00:10:06.583Z","Research-reported exposed Elasticsearch database","https:\u002F\u002Fwww.safetydetectives.com\u002Fblog\u002Fmycastingfile-leak-report\u002F",[17,19,20,21,22],"https:\u002F\u002Finformationsecuritybuzz.com\u002Fexpert-commentary-us-actor-casting-company-mycastingfile-com-leaked-private-data\u002F","https:\u002F\u002Fdevolutions.net\u002Fblog\u002Fthe-biggest-data-breaches-of-2020","https:\u002F\u002Fmycastingfile.com\u002F","https:\u002F\u002Fmycastingfile.com\u002Fprivacy-policy\u002F",260000,"known","unknown","en",[26,28],"tr",{"en":30,"tr":31},{"slug":9},{"slug":9},"High",[34,35,36,37,38,39,40,41,42,43,44,45],"Names","Email addresses","Phone numbers","Physical addresses","Dates of birth","Geographic locations","Profile photos","Physical attributes","Ethnicities","Clothing sizes","Work histories","Vehicle information","\u003Cp>The MyCastingFile 2020 data breach is a comprehensive personal data incident reported to have been exposed on May 31, 2020, in the MyCastingFile service, which manages casting profiles of actor and extra candidates. The verified scope points to more than 260,000 user profiles and approximately 9.46 million records; the number of primary accounts shown to the user is limited to 260,000. The record includes fields such as full name, email address, phone number, physical address, date of birth, location information, profile photos, physical characteristics, ethnicity, clothing measurements, work history, and vehicle information. Therefore, the incident carries high risk not only for account security but also for physical security, fake casting offers, identity fraud, and the protection of child profiles.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The verified data types in this record cover the extensive personal details entered to create a casting profile. Name, email address, phone number, and physical address pose a direct risk for contact and identity matching. Date of birth, location data, and profile photos can help link a person's online presence to their real identity. Fields such as physical characteristics, height, weight, hair or skin color, ethnicity, clothing size, and vehicle information create a profile more sensitive than an ordinary account list. Work history and casting context can be used for fake role offers, fake production company messages, or scams involving promises of payment. This combination of data creates risks for targeted phishing, harassment, identity impersonation, and risks that extend into the physical world, even without containing a password.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified incident date should be considered as May 31, 2020; the published research was publicly reflected on July 16, 2020. Since the number of affected users was reported to be more than 260,000, a main record value of 260,000 should be used in the system. The remaining data repository was reported to be approximately 1 GB in size and contain 9,456,433 records; this number is not the unique user count, but the volume of profiles and associated records. Since passwords, payment cards, bank accounts, or government ID numbers were not verified in this record, these fields are not included. The claim that all photos are accessible is also not generalized; the report states that some photos are accessible and that the contents are stored at different hosting points. The scope is highly confidently verified within these limits.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>There are people in the highest risk group who include their real address, phone number, date of birth, current photo, vehicle information, and detailed physical characteristics in their casting profile. People seeking work as actors, extras, models, or set staff can easily be targeted with fake role offers that seem realistic. Child or young actor profiles carry separate risks; including physical characteristics and photos along with parent contact information increases the security impact. Work history and location information can help an attacker create more convincing messages based on a specific city, set, agency, or production name. For individuals using the same email address across social media, acting portfolios, and payment accounts, the risk of identity matching and fraud is higher.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The matched user should first review the contact information and publicly available portfolios on their MyCastingFile account. If the same phone number, email, and photos are used on different platforms, privacy settings should be tightened. If messages are received on behalf of a casting, agency, production company, or set team requesting fees, bank information, identity documents, address verification, or instant payment, the process should be stopped and verified independently of the channel. Parents should reduce extractable information such as photos, addresses, and school surroundings on accounts associated with a child profile. Suspicious messages should not be responded to, links should not be opened, and attachments should not be downloaded. Two-factor authentication should be enabled for the email used on the account, and critical accounts associated with the same email should also be checked separately.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>In casting and talent profile services, users should avoid sharing details that are not necessary for a job application and should periodically simplify their portfolio information. When photos, addresses, vehicles, and physical characteristics accumulate in the same profile, the risk is not limited to online fraud alone; the person's physical safety can also be affected. Therefore, it is important to use a separate email address, share phone numbers only with trusted agencies, remove old portfolios, and separate social media profiles from casting accounts. The key lesson for institutions operating platforms is not to leave search and profile data repositories open without authentication, to regularly review access logs, to establish a separate protection layer for child profiles, and to reduce unnecessary data retention periods.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>Seeing a MyCastingFile 2020 match in this record indicates that the related email address may have been included in a casting profile or talent application data. The match does not prove that a password or payment card was exposed; it means that verified risk involves the combined use of extensive personal profile fields, photos, contact information, location data, and physical characteristics. Users should review past casting applications, portfolio pages, social media links, and agency contacts; they should independently verify role, payment, travel, or identity confirmation requests from people they do not know. For institutions, the record should be classified as a high personal profile risk derived from a 2020 open data repository, and additional protection measures should especially be considered for child or young actor profiles.\u003C\u002Fp>","MyCastingFile (2020) Data Breach (260 Thousand Reported Records)","MyCastingFile (2020) Data Breach. 260 Thousand reported records are reported. Reported data: Names, Email addresses, Phone numbers. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fmycastingfile-2020.svg",false,{"name":7,"sector":52,"country":53,"website":10,"websiteArchiveUrl":54,"websiteStatus":54,"websiteCheckedAt":13},"Casting \u002F Talent Profiles","United States",""]