CSIDB logo
Incident

Uffizi Galleries

Incident posture

Attack window
Feb 2026
Location
Italy
Status
Unknown
CIA posture
Available to members
Updated
2026-08-27 00:59

Linked entities

Victim
Uffizi Galleries
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Feb 2026
Discovered
Feb 2026
Disclosed
Apr 2026
Resolved
Pending

Summary

The Uffizi Galleries experienced a cyberattack when malware entered through a vulnerability in the software that serves low‑resolution images on its website. Staff found email accounts suspended and internal servers unreachable. The attacker moved laterally across the network linking the museum, Palazzo Pitti and the Boboli Gardens, accessed the photographic archive server and reportedly extracted access codes, internal maps and CCTV camera locations. A ransom demand was sent to the director’s personal phone, accompanied by a threat to auction the stolen data on the dark web. The museum stated that no data were stolen, that its physical security systems remained isolated, and that only email services were disrupted while backups of the archive were intact. Italian authorities opened an investigation for attempted extortion and unauthorized computer access, and technical analysis linked the incident to the BabLock ransomware strain.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

3 techniques

Description

On the weekend of 1 February 2026 staff at the Uffizi Galleries arrived on Monday morning to discover that their email accounts had been suspended, internal servers were unreachable, and the administrative backbone of the museum was effectively dark. Investigators traced the intrusion to a vulnerability in the software that manages low‑resolution images on the museum’s website, which allowed malware to gain an initial foothold. Within hours the attackers moved laterally through the network that links the Uffizi, Palazzo Pitti and the Boboli Gardens, reaching the photographic archive server. The Italian daily Corriere della Sera reported that the intruders had accessed the entire museum network, extracted access codes, internal maps and CCTV camera locations, taken control of the photographic server and sent a ransom demand directly to the personal phone of director Simone Verde, accompanied by a threat to auction the stolen data on the dark web. The Uffizi issued a swift and categorical response, stating that nothing was stolen, no security systems were compromised and describing the incident as “nothing like the Louvre.” While denying nearly all of the claims made by Corriere della Sera, the museum confirmed that malware had penetrated administrative systems in late January and early February, that staff email had been disrupted, that Italian authorities had opened an investigation for attempted extortion and unauthorised computer access, and that technical commentary linked the attack to the BabLock ransomware strain (also known as Rorschach), previously seen in an incident at La Sapienza University of Rome.

In its official statements the Uffizi emphasized that ticketing and visitor areas remained unaffected and that the museum stayed open throughout the incident, with the only operational disruption being the time required to restore backups from its secure archives. The museum noted that its physical security systems operate on closed internal networks that are inaccessible from outside, that no passwords were stolen and that camera locations are publicly visible, making their discovery unremarkable. It also affirmed that the photographic archive possessed a complete backup, which it relied on for recovery. The Uffizi disclosed that it had moved Medici‑era treasures to the Bank of Italy and had sealed certain doorways with bricks and mortar, actions it attributed to planned renovations and fire‑safety compliance rather than to the cyber incident. Additionally, the museum said that the replacement of analogue surveillance cameras with digital ones had been recommended by police in 2024 and was accelerated after the Louvre heist, a detail it presented as part of its ongoing security upgrades.

The immediate impacts of the attack included the suspension of staff email, the unavailability of internal servers and a temporary darkening of the administrative network, while public‑facing services such as ticketing, entry controls and gallery operations continued without interruption. No physical artifacts were reported as stolen or damaged, and the Uffizi maintained that its physical security posture was not compromised by the digital intrusion. The investigation by Italian authorities into attempted extortion and unauthorised computer access remained ongoing, with the BabLock/Rorschach ransomware linkage cited as a notable technical detail. The episode underscored how a modest software vulnerability could provide a pathway for attackers to traverse interconnected historic sites and prompted a public dispute over the extent of data exposure, even as the museum insisted that its core operations and collections were unharmed.

Sources

Sources available to members: 1 source.

CSIDB