Ransomware Attack on the Uffizi Gallery: Italian Cultural Heritage in the Crosshairs of Cybercrime
On the night between Saturday, February 1 and Sunday, February 2, 2026, one of the most important museums in the world fell victim to organized cybercrime. The Uffizi Gallery in Florence was hit by a ransomware attack that compromised the institution's administrative servers, paralyzing the museum's internal operations for several days. The attack coincided with a similar cyber assault on Rome's La Sapienza University, at a time of heightened tension surrounding the Milan-Cortina 2026 Winter Olympics. The incident serves as a wake-up call for the entire Italian cultural sector, traditionally considered a secondary target by cybersecurity analysts.
Attack Timeline
The intrusion took place during the nighttime hours of the weekend, a window strategically chosen by the attackers to exploit the reduced IT surveillance typical of non-working days. The Gallery's administrative server was the primary target: the virus struck systems dedicated to internal management activities, including staff email, human resources, procurement, and internal communications. The institutional website, ticketing system, surveillance cameras, and visitor management software continued to operate normally, allowing the museum to remain open to the public without interruption.
Director Simone Verde immediately filed a report with the Postal Police, activating containment and recovery procedures. Staff were ordered not to turn on their computers until authorized by the IT department, to avoid remote connections to the museum's systems, and to immediately change their email account passwords. A specialized firm was engaged to perform a complete remediation of all machines. By Wednesday, February 5, according to La Nazione, systems had been fully restored thanks to backup activation.
Attribution: the Medusa Group
According to journalistic reports, particularly those from Eco Vicentino and Cybersecurity360, the attack was claimed by the criminal group Medusa, one of the most active ransomware-as-a-service (RaaS) collectives worldwide. Medusa has been operating since June 2021 and is distinguished by its use of a double extortion model: victims' data is encrypted and simultaneously exfiltrated, with the threat of publication on a dedicated leak site if the ransom is not paid. Evidence suggests the group operates from Russia or an allied state, as it systematically avoids targeting organizations within the Russian Federation and the Commonwealth of Independent States (CIS) countries.
As of February 2025, according to a joint CISA-FBI-MS-ISAC advisory, Medusa had already struck over 300 organizations in critical sectors including healthcare, education, technology, and manufacturing. In February 2026, the group was also linked to operations by the North Korean Lazarus Group, which adopted Medusa ransomware for campaigns against healthcare facilities and non-profit organizations in the United States and the Middle East.
Impact and Damage Analysis
Initial assessments, conducted by the Uffizi's technicians in collaboration with the Postal Police and with the support of the National Cybersecurity Agency (ACN), found no evidence of data loss or critical irreversible damage to the museum's infrastructure. However, the operational impact was significant: administrative services remained blocked for several days, with consequences for human resources, accounting, procurement, and internal planning. The fact that the ticketing, video surveillance, and visitor services systems were on separate networks prevented far worse consequences, demonstrating how even partial network segmentation can limit the blast radius of an attack.
The most concerning aspect remains the possible exfiltration of administrative data. Although no data leaks have been confirmed, Medusa's operational model involves extracting data before encryption: internal documents, personnel records, supplier contracts, and institutional correspondence may have been acquired by the attackers. At the time of writing, no data relating to the Uffizi Gallery has appeared on Medusa's leak site, but the risk cannot be ruled out.
A Growing Trend: Cultural Institutions Under Attack
The attack on the Uffizi is not an isolated case. European cultural institutions have become increasingly frequent targets of cybercrime and state-sponsored operations. In July 2025, the Museum national d'Histoire naturelle in Paris was hit by a cyberattack that forced the cancellation of an exhibition. In October 2024, the Art Gallery of Ontario in Canada suffered a cybersecurity incident that compromised internal systems. In 2024, the Opera di Santa Maria del Fiore in Florence lost 1.785 million euros to a BEC (Business Email Compromise) scam, in which criminals intercepted email communications with a construction contractor, replacing the bank details for payment. Even the Louvre in Paris revealed serious vulnerabilities: a 2014 audit had flagged that surveillance system passwords were as trivial as "Louvre" and "Thales", yet they had not been changed for over a decade.
On March 31, 2026, Internet Archive Europe hosted the webinar "Cultural Heritage Under Attack: Saving Cultural Data in Times of Crisis", dedicated to the threats facing cultural heritage collections, from armed conflicts to cyberattacks. The event confirms the growing international awareness of the vulnerability of cultural institutions in the digital domain.
Why Museums Are Vulnerable
Cultural institutions have characteristics that make them particularly exposed to cyber threats. IT budgets have historically been low compared to other sectors: the Louvre, for example, invested 169 million euros in acquisitions versus 87 million in security. The accelerated digitization of collections and public services has enormously expanded the attack surface without a corresponding strengthening of defenses. Technical staff is often limited, cybersecurity training is lacking, and legacy systems are widespread. Moreover, museums and archives hold sensitive data — loan information, insurance details, donor records, personnel data — whose value to criminals should not be underestimated. The perception of being "off the radar" of attackers has fostered a false sense of security that recent events have definitively disproved.
Regulatory Implications: NIS2 and the Cultural Sector
The attack on the Uffizi raises urgent questions about the security posture of Italian cultural institutions in the context of the NIS2 Directive. Although museums and galleries do not directly fall among the "essential" or "important" entities listed by the directive, their dependence on digital infrastructure and their relevance to national identity suggest that comparable security standards should be voluntarily adopted. The ACN has already developed the "Suite Museum Cloud" platform to provide digital infrastructure to Italian museums, but the incident demonstrates that technological protection must be accompanied by governance, training, and structured incident response procedures.
Operational Recommendations for Cultural Institutions
- 1.Implement rigorous network segmentation between administrative systems, ticketing/visitor services systems, and surveillance systems. The Uffizi's architecture, which isolated public-facing services, proved its effectiveness in containing the attack's impact.
- 2.Adopt a zero-trust architecture with multi-factor authentication (MFA) on all access points, particularly for email, VPN, and remote management systems. Compromised credentials remain the most common entry vector for ransomware groups.
- 3.Implement offline and immutable backup systems with periodic restoration tests. The Uffizi's ability to restore systems within days was made possible by functioning backups.
- 4.Activate 24/7 SOC monitoring, particularly during weekends and holidays, when attackers prefer to strike. The Uffizi attack occurred on a Saturday night, exploiting reduced IT surveillance.
- 5.Conduct security awareness training programs for all staff, with phishing simulations and payment verification procedures. The BEC scam at the Opera di Santa Maria del Fiore demonstrates that the human factor remains the most critical weak point.
- 6.Prepare a tested and updated Incident Response Plan with clear procedures for escalation, communication, and coordination with the relevant authorities (Postal Police, ACN, CSIRT Italia).
The attack on the Uffizi Gallery is an unequivocal signal: no organization is safe from cybercrime, regardless of its sector. Italian cultural institutions safeguard heritage of inestimable value — not only artistic, but also in terms of data, institutional relationships, and international reputation. Protecting this heritage in the digital domain is no longer optional, but a strategic necessity. AEGIDA supports organizations in adopting modern security architectures, from risk assessment to zero-trust model implementation, through to NIS2 compliance and staff training.