A cyberattack on Irec SAS, the French subsidiary of online ticketing provider Vivaticket, disrupted online reservations for nearly 3,500 museums, monuments, and cultural sites across Europe. Major attractions affected included the Louvre, Musée d'Orsay, Musée du Quai Branly, the Arc de Triomphe, the Eiffel Tower, and Notre-Dame de Paris, with some booking services remaining unavailable after the intrusion. French authorities, including the national cybersecurity agency and law enforcement, were engaged to determine the scope of the incident, while impacted institutions began notifying customers and assessing operational and financial fallout.
The RansomHouse ransomware operation claimed responsibility and said it exfiltrated personal and reservation-related data from Irec systems, including names, email addresses, purchase history, reservation details, login timestamps, account metadata, and country of residence. Vivaticket said its investigation had found no evidence that credit card or banking data was accessed, but the breach raised concerns over exposure of customer information tied to travel and cultural visits across France and other European destinations.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Some affected organizations and ticketing services remained unavailable after the breach, and France's Ministry of Culture said each impacted institution was still evaluating the financial consequences. The disruption highlighted ongoing operational fallout across the cultural sector.
Impacted organizations began notifying customers of the breach while Vivaticket worked with the French National Cyber Security Directorate and law enforcement to determine the scope of the incident. Vivaticket said it found no evidence that credit card or banking information had been accessed.
The RansomHouse ransomware operation listed Irec on its leak site and claimed it stole personal and reservation-related data, including names, purchase history, reservation details, email addresses, login timestamps, account metadata, and country of residence. This public claim marked the incident as both disruptive and potentially data-compromising.
In early March, a cyberattack against Irec SAS, the French subsidiary of ticketing platform Vivaticket, disrupted online reservations for nearly 3,500 museums, monuments, and cultural sites across Europe. Major affected sites included the Louvre, Musee d'Orsay, Arc de Triomphe, Eiffel Tower, and Notre-Dame de Paris.
A cyberattack on a software vendor used by France's health ministry led to the theft of medical details affecting about 15.8 million people in France. Reporting indicates private health information was included in the compromised data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybernews.com
Open sourcethe420.in
Open sourcetechradar.com
Open sourcefrance24.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.