Curator Live
Incident posture
Linked entities
- Victim
- Curator Live
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A security researcher found that Curator Live had left a substantial collection of photos from weddings, engagement parties and other events, together with phone numbers, openly accessible through its API. The exposed data, estimated at over 100 gigabytes, included images of guests drinking and sometimes children, and the researcher’s attempts to notify the company received no response, leaving the material available for anyone to download.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In early November 2025 a security researcher attended a wedding where the DJ company had deployed a Curator Live photo booth. The booth was configured to capture four images per session, print them, and then prompt participants for a phone number to receive digital copies. After providing his number, the researcher received a text message containing a link to Curator Live’s API. Following that link he discovered a publicly accessible repository containing at least 100 gigabytes of photos, associated phone numbers, and metadata from events such as weddings, engagement parties, children’s gatherings, and a NASA‑branded function. He subsequently emailed Curator Live in November detailing the exposure and requesting remediation, but received no reply.
The exposed collection included images of people drinking and celebrating, some of which depicted intoxicated behavior, and in certain cases phone numbers could be matched to specific photos. The researcher noted that the material could reveal intimate images and that users generally had no awareness that their photos were being retained by a third party. 404 Media reviewed a smaller sample of the photos and confirmed the presence of the described content. The researcher emphasized that the unrestricted availability of the data violated reasonable expectations of privacy and allowed any stranger to download and browse the images.
Despite the researcher’s outreach, Curator Live did not address the vulnerability, and the data remained accessible at the time of reporting. 404 Media sought comment from the company for its February 3, 2026 article but received no response. The article, titled “Wedding Photo Booth Company Exposes Customers’ Drunken Photos,” disclosed the findings and noted that the exposure was ongoing. No further remediation or public statement from Curator Live has been recorded in the source material.
Sources
Sources available to members: 1 source.