
Over the weekend, cybercriminals launched a ransomware attack on a centralized system containing the financial data of around 40 French museums, as reported by Le Parisien. The breach was detected by a security specialist at the Grand Palais Museum, which is currently hosting Olympic fencing and martial arts competitions.
The attack resulted in the shutdown of access to the Grand Palais servers, subsequently impacting the operations of 36 bookstores and boutiques affiliated with major museums, including the Louvre, the Palace of Versailles, Orsay, and the Picasso Museum. However, the museums’ daily operations remained unaffected.
Matthias Grolier, chief of staff at the Louvre, clarified on social media that the ransomware attack did not directly target the Louvre itself. He emphasized vigilance and expressed solidarity with affected colleagues.
The unidentified hacker group responsible for the attack has demanded a ransom in cryptocurrency, threatening to release encrypted data within 48 hours if their demands are not met. It remains unclear if negotiations with the hackers have taken place. The French National Cybersecurity Agency (ANSSI) confirmed it was alerted to the incident and noted that the affected system was not connected to the operations of the ongoing Olympic Games. As of Tuesday, no data leaks had been reported.
French authorities, including the police, have initiated a criminal investigation into the attack. The incident has raised concerns about potential connections to the Olympic Games, a period often targeted by cybercriminals seeking financial gain or political leverage. Researchers from Recorded Future’s Insikt Group have warned that significant events like the Olympics present opportunities for ransomware attacks, given the heightened pressure on companies to avoid service interruptions.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543