Ransomware attack hit Grand Palais and dozens of French museums during Paris Olympics

Organization
Grand Palais Reunion des musees nationaux
Exploit
Ransomware
Industry
Museums and Cultural Venues

The Reunion des musees nationaux (Rmn), the French public body that operates the Grand Palais, disclosed in early August 2024 that its central computer system had been hit by ransomware. The intrusion was detected over the weekend of August 3 and 4, while the Grand Palais was serving as an Olympic venue hosting fencing and taekwondo competitions.

Because the compromised system was shared, the attack reached well beyond a single site. Reporting at the time put the number of affected institutions at roughly 40 other museums and cultural venues that used the Rmn platform for shops, ticketing and financial data. The attackers threatened to publish financial information unless a cryptocurrency ransom was paid within 48 hours.

Rmn said it immediately disconnected the systems it considered vital and called in ANSSI, the French national cybersecurity agency. The Paris prosecutor's office opened an investigation into attacks on an automated data processing system and assigned it to the BL2C, the cybercrime brigade of the judicial police. Preliminary findings reported at the time indicated that no data had been extracted from the compromised system.

Officials stressed that the information systems supporting the Olympic and Paralympic Games were separate and were not implicated, and no competitions were disrupted. As of late August 2024 no group had been publicly identified as responsible, no ransom had been paid, and the investigation remained open.

Sources