Gallery Systems ransomware attack took museum collection databases offline
- Organization
- Gallery Systems
- Exploit
- Ransomware
- Industry
- Software
Gallery Systems, a supplier of collection management software used by museums, told clients on December 28, 2023 that computers running its software had been encrypted and could no longer operate. The company said it isolated the affected systems, took others offline as a precaution, brought in third-party cybersecurity specialists and contacted law enforcement.
Two products were disrupted. TMS is the internal collections database that holds provenance records, loan agreements, donor names, shipping details and the storage locations of objects. eMuseum is the public-facing tool that lets visitors browse a museum's collection online. Gallery Systems says its software is used by more than 800 institutions.
Museums that reported outages included the Museum of Fine Arts, Boston, the Rubin Museum of Art in New York, Crystal Bridges Museum of American Art in Arkansas and the Frances Lehman Loeb Art Center at Vassar College. The Metropolitan Museum of Art, which uses Gallery Systems software but hosts its own database, said it was not affected, as did the Whitney Museum of American Art.
The company told clients it was working continuously to restore access and would rebuild from the most recent available backup. No ransomware group publicly claimed the attack in the weeks that followed, which security observers noted was unusual, and Gallery Systems did not say whether any data had been copied. Curators at affected institutions were left without access to internal records while restoration continued.