MUST INCLUDE CAPITAL LETTERS AND SYMBOLS: THE LOUVRE’S PASSWORD WAS “LOUVRE”

Kevin Gorian
MUST INCLUDE CAPITAL LETTERS AND SYMBOLS: THE LOUVRE’S PASSWORD WAS “LOUVRE”

Imagine you’re in charge of security at one of the largest and most important museums in the world… Let’s say, the Louvre. Now imagine that, for the past 10 years, you’ve decided to ignore cybersecurity flaws in your system—or maybe you’ve reported them, but your superiors couldn’t care less. Let’s also assume that, for you, running Windows 2000 or Windows XP still feels like the best option available in the 21st century. And to top it all off, the password that grants access to the system guarding centuries of priceless history is, quite simply, “Louvre.”

Well, that’s it. A report from the Parisian newspaper Libération revealed, following the October 19th heist—where suspects disguised as construction workers stole the French crown jewels—that the Louvre’s protection system wasn’t exactly cutting-edge. The museum was running on turn-of-the-century software, thought adding a few symbols to its password was unnecessary, and, to make matters worse, ignored a decade (or two, according to Culture Minister Rachida Dati) of warnings that might—just might—have prevented one of the most significant robberies in recent years. From critical camera failures to outdated protocols and even insufficient physical barriers.

As of today, up to seven people have been arrested in connection with the crime (two being the main suspects), yet over 100 investigators, more than 150 DNA samples analyzed, and countless hours of security footage reviewed have not been enough to locate the pieces that vanished from the Galerie d’Apollon that day.

Trivia: It’s worth noting that a 2014 audit by ANSSI (France’s national cybersecurity agency) already pointed out that the museum used “Louvre” as the password for its security camera system. It’s unknown whether that login was still active in 2025. But one might assume that… it was?