Museum Hit In Brazen Heist Reportedly Committed Classic Security Blunder
The Louvre museum at one point had its own name as one of the passwords to its video surveillance system, French newspaper Libération first reported. The iconic Paris museum in October was the scene of a heist where…


The Louvre museum at one point had its own name as one of the passwords to its video surveillance system, French newspaper Libération first reported.
The iconic Paris museum in October was the scene of a heist where thieves stole several valuable Napoleonic jewels. The French National Cybersecurity Agency (ANSSI) audited the Louvre’s security system back in 2014, when it found that the password to the server overseeing the museum’s video surveillance system was simply “LOUVRE,” and warned that the same server could be exploited to commit a robbery if accessed by the wrong person, Libération reported.
In addition to the eponymous password to the video surveillance, the museum’s password to access a security program published by French cybersecurity company Thales Group was “THALES” at the time of the audit, according to Libération.
“An attacker who manages to take control of this network would be able to facilitate damage or even theft of artworks,” stated ANSSI in its 2014 audit report, obtained by Libération, originally in French.
“The applications and systems deployed on the security network present numerous vulnerabilities,” the audit report added. “From this access point, it is then possible to compromise the security network … to damage the video surveillance system by compromising outdated servers … to modify the access rights granted to a badge by compromising the database used by the badge access control system,” the audit report added.
The Louvre had also used the then-14-year-old operating system Windows 2000 for its office network at the time of the 2014 audit, Libération reported. ANSSI called the system “obsolete” and urged the museum to change its passwords so they were more complex than “LOUVRE” and “THALES.”
It is unclear whether the passwords had been changed following the audit, and, if so, what they had been changed to.


