A cyberattack on one of Italy's largest cultural institutions reveals a sector that has dominated physical security and ignored digital. After the first weekend of February 2026, staff at the Uffizi Galleries in Florence found their email accounts suspended, internal servers inaccessible and the administrative backbone of the famous museum effectively shut down.

The malware had entered through a vulnerability linked to the low-resolution image management software on the museum’s website. Within hours, the attacker had spread through the network connecting the Uffizi, Palazzo Pitti and the Boboli Gardens, affecting the photographic archive server and sending a ransom demand directly to the personal phone of director Simone Verde.
See also: North Korean hackers use GitHub as C2 in attacks
The Uffizi’s official response was immediate and categorical: nothing was stolen, no security system was breached , and the incident was not “like the one at the Louvre.” This comparison, intended to reassure the public, may be the most revealing thing ever said about the state of cultural security in Europe.
The cyberattack on the Uffizi isn't interesting for what it destroyed. It's interesting for what it revealed: a sector that has spent centuries perfecting the art of physical protection but fails to take into account digital security.
The reference to the Louvre is not coincidental. On October 19, 2025, thieves disguised as construction workers used a freight elevator to reach a second-floor balcony of the Louvre, break a window, and steal jewelry worth an estimated 88 million euros in less than eight minutes.
A subsequent Senate investigation revealed that only 39% of the museum's rooms were covered by CCTV, that an external camera was pointed in the wrong direction, and that the surveillance system's password was, simply, "Louvre.".
Director Laurence des Cars finally resigned in February 2026. The jewels remain missing.
See also: Iranian password-spraying campaign targets Israeli organizations

Uffizi Galleries: Digital attack
The Uffizi, then, wanted to make this distinction. Its attack was digital, not physical. The museum remained open throughout the incident. The ticket and visitor areas were not affected.
The only operational disruption was the time it took to restore the backups. But the distinction, while technically accurate, hides a more inconvenient truth. The Louvre robbery was an old crime committed against an old vulnerability: a poorly guarded window. What happened at the Uffizi falls into a completely different category, where the threat is invisible, the perimeter is infinite, and the damage may not be fully understood for months.
What's really going on with the attack?
The gap between what the Corriere della Sera newspaper reported and what the Uffizi acknowledged remains wide. The newspaper described a prolonged intrusion in which attackers gained access to the museum's entire network, extracted passwordscamera locations CCTV, took control of the photographic server and then sent a ransom demand accompanied by a threat to auction the compromised data on the dark web.
See also: Qilin and Warlock ransomware: Using vulnerable drivers to disable EDR

The Uffizi has denied almost all of this. It said its physical security systems operate on closed internal networks, inaccessible from the outside. It said no passwords were stolen. What is not disputed is that malware infiltrated administrative systems in late January and early February. It also said that staff email was disrupted, that Italian authorities have launched an investigation into attempted extortion and unauthorized access to computers, and that technical comments have linked the incident to BabLock, a ransomware strain also known as Rorschach, which was previously linked to an attack on Rome’s La Sapienza University.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Italy, a country that holds some of the greatest cultural treasures on Earth, now faces both categories of threats simultaneously: old-fashioned “break and grab” and silent digital invasion.
