The dumbest password in history: How โ€œLOUVREโ€ led to a masterpiece of failure

When world-class art met zero cybersecurity, the result was a lesson every business leader should remember: Technology is not just a commodity!

๐Ÿšจ๐“๐ก๐ž ๐ ๐ซ๐ž๐š๐ญ๐ž๐ฌ๐ญ ๐ซ๐จ๐›๐›๐ž๐ซ๐ฒ of all times exploited the ๐๐ฎ๐ฆ๐›๐ž๐ฌ๐ญ and ๐ฐ๐ž๐š๐ค๐ž๐ฌ๐ญ security flaw ever! Here are my learnings from this crazy event...

๐Ÿคฏ I know it's been some weeks ago, but I could not believe when I read that a critical security system at the Louvre used โ€œ๐‹๐Ž๐”๐•๐‘๐„โ€ as the admin password. I checked two sources. Then a third. WTH!

๐Ÿซ  And to make it even worse, this vulnerability was highlighted in a past audit in 2014, but ๐š๐ฉ๐ฉ๐š๐ซ๐ž๐ง๐ญ๐ฅ๐ฒ ๐ง๐จ๐จ๐ง๐ž ๐œ๐š๐ซ๐ž๐. And on top of that, the hardware, software and operating systems were super old and beyond end-of-life support.๐Ÿ“ธ Weeks before the night itself, intruders were ๐š๐›๐ฅ๐ž ๐ญ๐จ ๐š๐œ๐œ๐ž๐ฌ๐ฌ ๐ญ๐ก๐ž ๐œ๐š๐ฆ๐ž๐ซ๐š๐ฌ, learned the blind spots, changed some angles and planned their execution and when the eight minutes arrived, they were absolutely sure they wouldn't get caught.

โ†” Making a parallel comparison to other traditional industries, it's not difficult to have tech perceived as a commodity being led solely by business people. Not only because I come from tech, but this is the ๐›๐ข๐ ๐ ๐ž๐ฌ๐ญ ๐ฆ๐ข๐ฌ๐ญ๐š๐ค๐ž ๐ž๐ฏ๐ž๐ซ!

๐Ÿ‘” A Company Board must have members from all areas and critical awareness raised by any member should require immediate actions, no questions asked! Or, actually one question must always be on the table: ๐–๐ก๐š๐ญ ๐ก๐š๐ฉ๐ฉ๐ž๐ง๐ฌ ๐ข๐Ÿ ๐ฐ๐ž ๐๐จ๐ง'๐ญ ๐š๐œ๐ญ ๐ง๐จ๐ฐ?

๐Ÿ’ธI know budgets are tight and change takes time. But I also know โ€œLOUVREโ€ as an administrator key is not a question of budget or anything else, but rather just a dumb choice.

โ—๏ธIf you lead any business, try one small test this week. Pick a critical system, rotate the admin secret and watch who calls you. ๐“๐ก๐š๐ญ ๐œ๐š๐ฅ๐ฅ ๐ฅ๐จ๐  ๐ข๐ฌ ๐ฒ๐จ๐ฎ๐ซ ๐ฆ๐š๐ฉ.

๐Ÿš€ ZeroTrust Framework is the way to go, think about it...

more Insights
exclusive platform

AIย Omni Agent
Coming soon

Currently in beta. Soon available to all SMEs looking to 10x their output. Automate support, marketing, sales, content, and much more

Join the waitlist
Join the waitlist