Cyberattack on Dresden's State Art Collections Lasted Days, German Authorities Reveal

German authorities have revealed that a cyberattack on the Staatliche Kunstsammlungen Dresden (SKD) — the Dresden State Art Collections, one of Germany's largest museum networks — lasted multiple days, confirming that the breach first detected in January was more sustained than initially disclosed.
The SKD, which oversees fifteen museums across Dresden including the Gemäldegalerie Alte Meister and the Grünes Gewölbe, confirmed on January 22, 2026 that its IT infrastructure had been hit by what it called a "gezielter Hackerangriff" — a targeted hacker attack — discovered the previous day, January 21. Hackers took the institution's web pages offline, severing public access to ticketing, exhibition information and visitor services.
The new detail about the attack's duration was reported by German authorities and published on July 30, 2026 in ARTnews. The revelation adds a clearer timeline to an incident that had already prompted a law-enforcement response.
A Sonderkommission — a special investigative commission — was formed to probe the attack, as reported by Weltkunst in February 2026. The commission's formation signalled the seriousness with which German authorities treated the breach.
In the immediate aftermath, the impact was visible and practical. The SKD's website was unreachable for over a week. A telephone hotline (0351/4914-2000) was set up on January 26 to handle visitor enquiries while systems remained down, according to an SKD press release. The website came back online on January 29, eight days after the attack was first detected.
Beyond the website outage, operational restrictions at the museums persisted and investigations were ongoing through late January, according to Security Insider. The full extent of any data accessed or compromised during the attack has not been publicly detailed.
For a museum network that houses works by Vermeer, Rembrandt and Raphael and draws roughly two million visitors annually, the stakes of an IT breach extend well beyond a website going dark. Ticketing systems, collection databases, provenance records and staff communications all run through the same digital infrastructure. The SKD has not publicly stated whether collection data was accessed or exfiltrated.
What gives the new disclosure weight is the gap between the initial report and this update. The SKD moved quickly to restore public-facing services — the website was back within nine days, the hotline within five. But the revelation that the attack itself lasted multiple days suggests the intrusion ran deeper and longer than the restoration timeline alone implied. Whether the Sonderkommission has identified suspects or a motive has not been disclosed.


