Company Details
museum-national-d'histoire-naturelle
897
71,371
712
mnhn.fr
0
MUS_2988492
In-progress

Museum national d'Histoire naturelle Company CyberSecurity Posture
mnhn.frAu carrefour des sciences de la Vie, de la Terre et de l'Homme, le Muséum national d'Histoire naturelle se consacre, depuis des siècles, à la diversité biologique, géologique et culturelle, et aux relations entre les sociétés humaines et la nature. Le Muséum compte 2 185 personnes dont 500 chercheurs, forme environ 380 étudiants par an, abrite près de 66,8 millions de spécimens dans ses réserves et galeries, et a accueilli en 2023 plus de 3,8 millions de visiteurs payants dans 12 sites parisiens et régionaux.
Company Details
museum-national-d'histoire-naturelle
897
71,371
712
mnhn.fr
0
MUS_2988492
In-progress
Between 650 and 699

MNDN Global Score (TPRM)XXXX

Description: The Muséum national d'histoire naturelle de Paris has been severely impacted by a cyberattack since late July, rendering parts of its network and critical research tools inaccessible. The attack has disrupted research activities, expertise services, and access to natural heritage databases. While the museum's public areas remain open, the attack's scale suggests potential data exfiltration, with cybercriminals possibly targeting valuable research data for commercial exploitation. The institution has refused to pay any ransom, aligning with French public administration policies. The duration of the outage and recovery timeline remain uncertain, highlighting the attack's severity.
Description: The **Muséum national d'Histoire naturelle (MNHN)** in Paris suffered a **massive ransomware attack** in late July 2025, crippling its internal network and disrupting critical operations. The attack forced the cancellation of the high-profile *Tropical Autumn: Palms, Treasures and Secrets* exhibition, a major seasonal event expected to draw significant public interest. Beyond cultural losses, the breach paralyzed research activities—600 scientists faced delays, with some losing **€30,000–50,000 in unspendable research funds** due to inaccessible systems. Digital tools for libraries, collections, and expertise were rendered unusable, halting parts of **French natural science research**. While public-facing sites (galleries, zoos, gardens) remained open, digitally dependent services (e.g., themed tours) were suspended. The institution filed a complaint, refusing ransom payments, and prioritized system restoration. The attack underscores the growing vulnerability of cultural institutions to cyber threats, with **40 French museums targeted similarly in the past year**. Recovery efforts focus on securing infrastructure, but the financial, operational, and reputational damage persists.


Museum national d'Histoire naturelle has 140.96% more incidents than the average of same-industry companies with at least one recorded incident.
Museum national d'Histoire naturelle has 212.5% more incidents than the average of all companies with at least one recorded incident.
Museum national d'Histoire naturelle reported 2 incidents this year: 1 cyber attacks, 1 ransomware, 0 vulnerabilities, 0 data breaches, compared to industry peers with at least 1 incident.
MNDN cyber incidents detection timeline including parent company and subsidiaries

Au carrefour des sciences de la Vie, de la Terre et de l'Homme, le Muséum national d'Histoire naturelle se consacre, depuis des siècles, à la diversité biologique, géologique et culturelle, et aux relations entre les sociétés humaines et la nature. Le Muséum compte 2 185 personnes dont 500 chercheurs, forme environ 380 étudiants par an, abrite près de 66,8 millions de spécimens dans ses réserves et galeries, et a accueilli en 2023 plus de 3,8 millions de visiteurs payants dans 12 sites parisiens et régionaux.


The Czech Center Museum Houston is a 501(c)(3) non-profit educational and cultural arts organization. Proud to be one of Houston's eighteen fine museums, the CCMH strives to preserve and expand public knowledge of Czech and Slovak heritage with the ultimate goal of serving as a catalyst for the exp

The Aquarium of the Pacific is Southern California’s largest Aquarium. It displays about 12,000 animals and more than 100 exhibits that celebrate the planet’s largest and most diverse body of water, the Pacific Ocean. Its galleries represent the frigid waters of the Northern Pacific, the temperate S

The Bowers Museum enriches lives through the world's finest arts and cultures. To achieve its mission, the Bowers offers exhibitions, lectures, art classes, travel programs, children's art education programs, and other special community programs. The Bowers is proud to be honored by the local comm

National Gallery Singapore is a leading visual arts institution overseeing the largest public collection of modern art in Singapore and Southeast Asia. Situated at the birthplace of modern Singapore, in the heart of the Civic District, the Gallery is housed in two national monuments – City Hall and

The Morris Museum of Art was founded in 1985 and opened to the public in 1992. It is the oldest museum in the country that is devoted to the art and artists of the American South. The museum’s permanent collection holds more than six thousand works of art that date from the late-eighteenth century t

The Museum at Eldridge Street is housed in the Eldridge Street Synagogue, a magnificent National Historic Landmark that has been meticulously restored. Opened in 1887, the synagogue is the first great house of worship built in America by Jewish immigrants from Eastern Europe. Today, it is the only r
.png)
A ransomware attack against the Grand Palais in Paris is being investigated, but the Olympic games have gone ahead unaffected.
A new exhibit on cybersecurity called "Weapons of Mass Disruption" at the International Spy Museum in Washington, DC.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Museum national d'Histoire naturelle is http://www.mnhn.fr.
According to Rankiteo, Museum national d'Histoire naturelle’s AI-generated cybersecurity score is 653, reflecting their Weak security posture.
According to Rankiteo, Museum national d'Histoire naturelle currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Museum national d'Histoire naturelle is not certified under SOC 2 Type 1.
According to Rankiteo, Museum national d'Histoire naturelle does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Museum national d'Histoire naturelle is not listed as GDPR compliant.
According to Rankiteo, Museum national d'Histoire naturelle does not currently maintain PCI DSS compliance.
According to Rankiteo, Museum national d'Histoire naturelle is not compliant with HIPAA regulations.
According to Rankiteo,Museum national d'Histoire naturelle is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Museum national d'Histoire naturelle operates primarily in the Museums, Historical Sites, and Zoos industry.
Museum national d'Histoire naturelle employs approximately 897 people worldwide.
Museum national d'Histoire naturelle presently has no subsidiaries across any sectors.
Museum national d'Histoire naturelle’s official LinkedIn profile has approximately 71,371 followers.
Museum national d'Histoire naturelle is classified under the NAICS code 712, which corresponds to Museums, Historical Sites, and Similar Institutions.
No, Museum national d'Histoire naturelle does not have a profile on Crunchbase.
Yes, Museum national d'Histoire naturelle maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/museum-national-d'histoire-naturelle.
As of December 03, 2025, Rankiteo reports that Museum national d'Histoire naturelle has experienced 2 cybersecurity incidents.
Museum national d'Histoire naturelle has an estimated 2,131 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack and Ransomware.
Detection and Response: The company detects and responds to cybersecurity incidents through an incident response plan activated with yes, and law enforcement notified with yes, and communication strategy with public statements and reassurance to visitors, and incident response plan activated with yes (crisis unit established), and law enforcement notified with yes (complaint filed with paris public prosecutor's office; investigation handled by specialized cybercrime section), and remediation measures with gradual restoration of services, remediation measures with reinforcement of digital security..
Title: Cyberattack on Muséum national d'histoire naturelle de Paris
Description: The Muséum national d'histoire naturelle de Paris has been suffering from a severe cyberattack since late July, rendering several tools and parts of its system inaccessible. The attack has affected research activities, expertise tools, and access to collections. The museum has filed a complaint, and an investigation is ongoing. The museum has refused to pay any ransom.
Date Detected: Late July
Date Publicly Disclosed: Late July
Type: Cyberattack, possible ransomware
Motivation: Possible data exfiltration for commercial purposes
Title: Massive Ransomware Attack on Muséum national d'Histoire naturelle (MNHN)
Description: A massive ransomware attack in late July 2025 paralyzed the Muséum national d'Histoire naturelle (MNHN) in Paris, disrupting its digital infrastructure, research activities, and forcing the cancellation of the 'Tropical Autumn: Palms, Treasures and Secrets' exhibition. The attack affected internal networks, research funding, and digital tools critical to the institution's operations. No public data was compromised, but the institution refused to pay the ransom. A crisis unit was established to restore services and enhance cybersecurity.
Date Detected: Late July 2025
Date Publicly Disclosed: Late July 2025 (exact date unspecified)
Type: Ransomware attack
Common Attack Types: The most common types of attacks the company has faced is Cyber Attack.

Data Compromised: Possible data exfiltration
Systems Affected: Research tools, expertise tools, collection consultation services
Downtime: Several weeks
Operational Impact: Significant disruption to research and administrative activities

Data Compromised: Possible data exfiltration (no public data confirmed compromised)
Systems Affected: Internal computer networkDigital tools for operationsResearch control systemsOnline tools for research, expertise, libraries, and collection consultationDigital applications for themed tours
Downtime: Ongoing since late July 2025 (as of report date)
Operational Impact: Cancellation of 'Tropical Autumn: Palms, Treasures and Secrets' exhibition (October 16–November 24, 2025)Disruption of research activities for 600 scientistsLoss of €30,000–€50,000 in research funding per team (unspendable due to system inaccessibility)Suspension of themed tours dependent on digital applications
Brand Reputation Impact: Potential reputational damage due to cancellation of high-profile exhibition and operational disruptions
Identity Theft Risk: None (no public data compromised)
Payment Information Risk: None
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Unspecified (possible exfiltration; no public data confirmed).

Entity Name: Muséum national d'histoire naturelle de Paris
Entity Type: Museum, Research and Educational Institution
Industry: Natural Sciences, Education
Location: Paris, France

Entity Name: Muséum national d'Histoire naturelle (MNHN)
Entity Type: Cultural and scientific institution
Industry: Natural history, research, education, and cultural heritage
Location: 57 rue Cuvier, 5th arrondissement, Paris, France
Customers Affected: Botany enthusiasts (exhibition attendees), Researchers (600 scientists), General public (limited access to digital services)

Incident Response Plan Activated: Yes
Law Enforcement Notified: Yes
Communication Strategy: Public statements and reassurance to visitors

Incident Response Plan Activated: Yes (crisis unit established)
Law Enforcement Notified: Yes (complaint filed with Paris public prosecutor's office; investigation handled by specialized cybercrime section)
Remediation Measures: Gradual restoration of servicesReinforcement of digital security
Incident Response Plan: The company's incident response plan is described as Yes, Yes (crisis unit established).

Data Exfiltration: Possible

Type of Data Compromised: Unspecified (possible exfiltration; no public data confirmed)
Data Exfiltration: Possible (unconfirmed)
Personally Identifiable Information: None (confirmed)
Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Gradual restoration of services, Reinforcement of digital security, .

Ransom Paid: No (policy of French State and public administrations)
Data Encryption: Yes (partial paralysis of internal network)
Data Exfiltration: Possible (unconfirmed)

Legal Actions: Complaint filed with Paris public prosecutor's office
Ensuring Regulatory Compliance: The company ensures compliance with regulatory requirements through Complaint filed with Paris public prosecutor's office.

Source: La Tribune

Source: BFMTV

Source: franceinfo

Source: Article describing the cyberattack on MNHN
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: La Tribune, and Source: BFMTV, and Source: franceinfo, and Source: Article describing the cyberattack on MNHN.

Investigation Status: Ongoing

Investigation Status: Ongoing (handled by Paris public prosecutor's cybercrime section)
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Public statements and reassurance to visitors.

Customer Advisories: Visitors reassured that galleries, zoological parks, and gardens remain open and functional

Customer Advisories: Cancellation of 'Tropical Autumn' exhibition announced; no new dates providedGalleries, zoos, and gardens remain open; some themed tours suspended
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: were Visitors reassured that galleries, zoological parks, and gardens remain open and functional, Cancellation Of 'Tropical Autumn' Exhibition Announced; No New Dates Provided, Galleries, Zoos, And Gardens Remain Open; Some Themed Tours Suspended and .

Corrective Actions: Enhancement Of Digital Security Measures,
Corrective Actions Taken: The company has taken the following corrective actions based on post-incident analysis: Enhancement Of Digital Security Measures, .
Ransom Payment History: The company has Paid ransoms in the past.
Most Recent Incident Detected: The most recent incident detected was on Late July.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on Late July 2025 (exact date unspecified).
Most Significant Data Compromised: The most significant data compromised in an incident were Possible data exfiltration and Possible data exfiltration (no public data confirmed compromised).
Most Significant System Affected: The most significant system affected in an incident were Internal computer networkDigital tools for operationsResearch control systemsOnline tools for research, expertise, libraries, and collection consultationDigital applications for themed tours.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Possible data exfiltration and Possible data exfiltration (no public data confirmed compromised).
Most Significant Legal Action: The most significant legal action taken for a regulatory violation was Complaint filed with Paris public prosecutor's office.
Most Recent Source: The most recent source of information about an incident are BFMTV, Article describing the cyberattack on MNHN, franceinfo and La Tribune.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing.
Most Recent Customer Advisory: The most recent customer advisory issued were an Visitors reassured that galleries, zoological parks, and gardens remain open and functional, Cancellation of 'Tropical Autumn' exhibition announced; no new dates providedGalleries, zoos and and gardens remain open; some themed tours suspended.
.png)
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote code execution vector in a config class named Nemotron_Nano_VL_Config. When vllm loads a model config that contains an auto_map entry, the config class resolves that mapping with get_class_from_dynamic_module(...) and immediately instantiates the returned class. This fetches and executes Python from the remote repository referenced in the auto_map string. Crucially, this happens even when the caller explicitly sets trust_remote_code=False in vllm.transformers_utils.config.get_config. In practice, an attacker can publish a benign-looking frontend repo whose config.json points via auto_map to a separate malicious backend repo; loading the frontend will silently run the backend’s code on the victim host. This vulnerability is fixed in 0.11.1.
fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. Prior to 12.5.0, by crafting a malicious URL, an attacker could access routes that are not allowed, even though the reply.from is defined for specific routes in @fastify/reply-from. This vulnerability is fixed in 12.5.0.
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain javascript: URLs) as requiring strict URL security, enabling the injection of malicious scripts. This vulnerability is fixed in 21.0.2, 20.3.15, and 19.2.17.
Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causing damage or unavailability of server resources. Attackers can control the 'FileMd5' parameter to delete any file and folder.
Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the destination baseURL by prioritizing the value in the x-portkey-custom-host request header. The proxy route then appends the client-specified path to perform an external fetch. This can be maliciously used by users for SSRF attacks. This vulnerability is fixed in 1.14.0.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.