HomeSecurityUffizi Galleries: Cyberattack should worry every museum in Europe

Uffizi Galleries: Cyberattack should worry every museum in Europe

A cyberattack on one of Italy's largest cultural institutions reveals a sector that has dominated physical security and ignored digital. After the first weekend of February 2026, staff at the Uffizi Galleries in Florence found their email accounts suspended, internal servers inaccessible and the administrative backbone of the famous museum effectively shut down.

Uffizi Galleries

The malware had entered through a vulnerability linked to the low-resolution image management software on the museum’s website. Within hours, the attacker had spread through the network connecting the Uffizi, Palazzo Pitti and the Boboli Gardens, affecting the photographic archive server and sending a ransom demand directly to the personal phone of director Simone Verde.

See also: North Korean hackers use GitHub as C2 in attacks

The Uffizi’s official response was immediate and categorical: nothing was stolen, no security system was breached , and the incident was not “like the one at the Louvre.” This comparison, intended to reassure the public, may be the most revealing thing ever said about the state of cultural security in Europe.

The cyberattack on the Uffizi isn't interesting for what it destroyed. It's interesting for what it revealed: a sector that has spent centuries perfecting the art of physical protection but fails to take into account digital security.

The reference to the Louvre is not coincidental. On October 19, 2025, thieves disguised as construction workers used a freight elevator to reach a second-floor balcony of the Louvre, break a window, and steal jewelry worth an estimated 88 million euros in less than eight minutes.

A subsequent Senate investigation revealed that only 39% of the museum's rooms were covered by CCTV, that an external camera was pointed in the wrong direction, and that the surveillance system's password was, simply, "Louvre.".

Director Laurence des Cars finally resigned in February 2026. The jewels remain missing.

See also: Iranian password-spraying campaign targets Israeli organizations

Uffizi Galleries: Cyberattack should worry every museum in Europe

Uffizi Galleries: Digital attack

The Uffizi, then, wanted to make this distinction. Its attack was digital, not physical. The museum remained open throughout the incident. The ticket and visitor areas were not affected.

The only operational disruption was the time it took to restore the backups. But the distinction, while technically accurate, hides a more inconvenient truth. The Louvre robbery was an old crime committed against an old vulnerability: a poorly guarded window. What happened at the Uffizi falls into a completely different category, where the threat is invisible, the perimeter is infinite, and the damage may not be fully understood for months.

What's really going on with the attack?

The gap between what the Corriere della Sera newspaper reported and what the Uffizi acknowledged remains wide. The newspaper described a prolonged intrusion in which attackers gained access to the museum's entire network, extracted passwordscamera locations CCTV, took control of the photographic server and then sent a ransom demand accompanied by a threat to auction the compromised data on the dark web.

See also: Qilin and Warlock ransomware: Using vulnerable drivers to disable EDR

Uffizi Galleries: Cyberattack should worry every museum in Europe

The Uffizi has denied almost all of this. It said its physical security systems operate on closed internal networks, inaccessible from the outside. It said no passwords were stolen. What is not disputed is that malware infiltrated administrative systems in late January and early February. It also said that staff email was disrupted, that Italian authorities have launched an investigation into attempted extortion and unauthorized access to computers, and that technical comments have linked the incident to BabLock, a ransomware strain also known as Rorschach, which was previously linked to an attack on Rome’s La Sapienza University.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Italy, a country that holds some of the greatest cultural treasures on Earth, now faces both categories of threats simultaneously: old-fashioned “break and grab” and silent digital invasion.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS