Louvre’s Password Issues
The Louvre, facing scrutiny following a significant jewelry theft last month, reportedly used its own name as a password for video surveillance systems, according to newly reviewed confidential documents.
In 2014, the Paris museum sought an audit from the French National Agency for the Security of Information Systems to evaluate its security infrastructure.
Experts from the agency easily accessed the network using “LOUVRE” to enter a video surveillance server and “THALES” for software developed by defense contractor Thales, as detailed in the documents.
The agency’s specialists advised the Louvre to adopt more complex passwords, address vulnerabilities in its applications, and utilize systems that receive ongoing support from software vendors.
Both the 2014 and a subsequent 2017 audit highlighted reliance on outdated software and operating systems like Windows 2000 and Windows XP. The 2017 report noted that “technologies are aging and regularly experience technical malfunctions.”
The museum has not responded to inquiries regarding which recommendations from cybersecurity experts have been acted upon.
While suspects have been apprehended in connection with the October 19 heist, the stolen French crown jewels valued at approximately $102 million remain missing.


