The $102 Million
Password.
A post-incident analysis of the October 19, 2025 Louvre jewel heist, and a framework for engineering cyber-physical resilience.
12 Pages // Chris Armour // November 7, 2025
Key Findings
France's Court of Auditors found leadership had been warned of major weaknesses for a decade. Audits in 2014 and 2017 flagged critical vulnerabilities. Management funded high-profile acquisitions instead. The security modernization program started in 2015 is not scheduled to finish until 2032.
The video management system password was "Louvre". The vendor system used "THALES". Both were named in a 2014 ANSSI audit, alongside hosts still running Windows 2000. That gave attackers a ten-year window to study camera coverage remotely and map the blind spots.
The only external camera covering the Apollo Gallery perimeter was facing west and did not cover the window the thieves cut through. Interior alarms fired only after entry. Four people cleared the gallery in under seven minutes with a truck-mounted ladder and angle grinders.
The full report covers the 2014 ANSSI findings, the 2017 audit, the 2025 Court of Auditors indictment, a three-principle resilience framework (secure by default, MFA compensating controls for legacy OT, and risk quantification), and where the failure maps to ISO 27001 and NIS2.
Read the Case Study
Enter your email to receive the 12-page PDF