Read the recent thefts like a security engineer: the alarm always works, detection has already won, the failure is a race condition
Press enter or click to view image in full size
This piece is written for two readers. One is a security engineer who has never set foot in a museum vault. The other is a conservator who has never read a report on a network breach. The technical terms from both worlds are explained once, in half a line, when they first appear.
I’ll start with a word borrowed from computing: race condition. You have a race condition when two processes run in parallel and the outcome depends solely on which one finishes first. On who crosses the line, not on who is right. Keep it in mind.
Twelve days, two museums, the same sentence
On 15 August 2026, in Messina, while the Vara procession passed through the center and tens of thousands of people filled the streets, four works by Antonello da Messina left the regional museum. The alarm went off. According to the reconstruction in the Sicilian press it sounded at around 20:47, and for about fifteen minutes nothing happened, because no one alerted the police. Two guards were inside the museum. They read the signal as a false contact in the system and raised no alarm. A regional inspection later concluded that the equipment had worked, and that the failures lay in how the staff applied the procedures.
Twelve days later, on 27 August 2026, in Villena, in the province of Alicante, the script was different but the outcome identical. Here the timeline is documented to the minute by the newspaper eldiario.es:
- 5:16. The alarms go off at the town’s municipal sports hall, some distance from the museum. Investigators consider them a diversion, a lure to pull the patrols away.
- 5:20. Four minutes later, several people break through the entrance of the museum (the MUVI). The museum alarm sounds.
- 5:24. By the time the first Guardia Civil patrol receives the alert from the control room, the thieves have already taken 59 objects of gold, silver, iron and amber roughly three thousand years old, and have fled in several vehicles.
Four minutes inside the museum. Eight minutes if you count from the lure to the getaway. The vault was a certified Level 3 strongroom, with armored glass, steel plate, five concentric rings of alarms, thermal, seismic and motion sensors, and two security audits done before it opened. The alarms activated. The response didn’t make it in time. The newspaper puts it in six words: a pesar de la activación de las alarmas, despite the activation of the alarms.
Press enter or click to view image in full size
Let’s go back a year, to the Louvre, 19 October 2025. Galerie d’Apollon, museum just opened. A furniture lift on the Seine side, a window cut with an angle grinder, eight Crown jewels carried away. From entry at 9:34 to exit at 9:38, about four minutes pass. And here too, in the days that followed, the officials in charge stated that the security systems had worked normally.
There is a sentence that recurs, in slightly different words, in each of these cases: the alarm worked. It’s true. And that is exactly the point.
A genealogy: from nuclear plants to museums
The idea of studying art theft the way you’d study an attack on critical infrastructure is not new, and it isn’t mine.
In 1980 the RAND Corporation published a technical note (N-1498-SL, by Reinstedt and Westbury) that analyzed 121 high-value crimes to work out how exposed an American nuclear plant was to similar threats: how many perpetrators, what role insiders played, how much violence, how much deception. The assumption is that a complex robbery and an attack on a sensitive facility share the same structure.
In 2014 Sandia National Laboratories, laboratories of the U.S. Department of Energy, picked up that thread with a report (SAND2014–1790, “The Perfect Heist”) that reviews 23 sophisticated thefts. Once again, high-value theft serves as a model for thinking about threats to nuclear facilities.
In 2025 Sandra Clopés and Marc Balcells close the circle with a study published in the International Journal of Cultural Property, open access: a database of 40 museum thefts between 1990 and 2022, each analyzed across 46 variables. It is the most recent and systematic work on the subject, and from here on every percentage I cite comes from there, with explicit attribution, because our own sample is too small to compute any of our own.
The central finding of their study is this. In 90% of cases the security forces can only react after the fact. Only in 7.5% of cases do they react during the theft. And the explanation they give for the alarms is the most important of all: the sensors were not being disabled or bypassed; the thieves were simply faster at stealing than the sensors were at calling for help. Their words: thieves were faster stealing the pieces than the sensors alerting security forces.
This is the race condition. Two processes in a race: extracting the object, and the arrival of the response. Whoever finishes first wins. And in recent years the one who finishes first, almost always, is the one doing the stealing.
Dwell time in two worlds
In information security there is a metric that measures exactly this distance. It’s called dwell time: the interval between the moment an attacker enters a system and the moment they are detected. The firm Mandiant publishes it every year in its M-Trends report, as a global median in days.
In 2016 that median was 99 days: an attacker stayed inside a system for more than three months before anyone noticed. By 2020 it had dropped to 24 days, by 2023 to 10. In the last few years it has crept back up, to around 14 days, partly for a technical reason I’ll get to in the methodological note. But the underlying direction, over a decade, is clear: the cyber defender detects sooner. Detection is gaining ground.
Museum thefts are measured on a different scale. I’ll take only the cases for which a duration is documented by journalistic or institutional sources. The theft at the Isabella Stewart Gardner in Boston, in 1990, lasted 81 minutes: two fake policemen, let in by the guard, had all the time they needed to roam the galleries. Munch’s The Scream, stolen in Oslo in 1994: about fifty seconds. The Bode Museum in Berlin in 2017, with a hundred-kilo gold coin: an estimated window of about twenty-five minutes. Villena and the Louvre: four minutes. Albacete, also in 2026: ninety seconds.
These are two different orders of magnitude. Cyber defense operates on the scale of days and weeks; museum thefts are over in minutes, sometimes seconds. The point is that the two clocks move in opposite directions, and for opposite reasons.
Four correspondences
Anyone who works in a security operations center (a SOC, the room where network alarms are watched) will recognize four patterns.
Reconnaissance as a penetration test. Before a serious attack, an attacker studies the target and measures its reaction times. In 2010, at the Musée d’Art Moderne in Paris, a single man, Vjéran Tomic, prepared the job over six nights: he removed the screws from a window panel and filled the holes with brown modeling clay the same color as the frame, so he could work fast when the moment came. On the night of the theft he went in briefly, then waited a quarter of an hour on the bank of the Seine to see whether a silent alarm would trip. He had already noticed that the motion detectors stayed on green. In Villena, investigators reported that the thieves knew exactly what they were after and the precise response time they could count on. The term for this is revealed preferences: the attacker’s behavior reveals their estimate of the defender’s reaction time. If they act in four minutes, it’s because they’ve calculated that four minutes is enough.
Alert fatigue. A SOC receives thousands of alerts, and most are false positives. An operator who sees too many ends up trusting each one less, and sooner or later silences the real one. In Messina this is what happened, translated into a museum: the alarm sounded, and the person who heard it read it as yet another false contact. The signal was there. It was the signal-to-noise ratio that failed.
Responder saturation. A skilled attacker doesn’t wait for the defender to be free: they keep them busy elsewhere. In Villena the sports-hall alarm, tripped four minutes before the entry into the museum, was there to send the patrols in the wrong direction. Clopés and Balcells find that diversions and deceptions are standard in this kind of crime, present in 52.6% of the cases in their sample. It’s the physical counterpart of a diversionary attack that floods one service while the real strike lands on another front.
Compliance is not security. In my line of work it’s almost a motto: passing an audit means the controls work as specified, not that the specification is right. The Villena vault was certified Level 3 and had passed two audits. The controls did what they were designed to do: they detected the intrusion and sounded. But the specification took for granted that a sounding alarm leads to a response in time. Against a four-minute adversary it was wrong. The control was compliant. The system was vulnerable.
Why the theft resembles ransomware
One last piece of the analogy matters here, and it concerns what happens afterward.
A famous work of art is almost unsellable. Clopés and Balcells report that on the black market a stolen object is worth on average between 7 and 10% of its open-market price. The only party for whom that object is still worth a great deal is the one who lost it: the museum, the state, the insurer.
It’s the same geometry as a ransomware attack, the malicious software that encrypts a victim’s data and demands a ransom. The encrypted data has no value to anyone else. The only possible buyer is the owner, who buys back access to what already belongs to them.
The theft at Dresden’s Green Vault, in November 2019, followed this curve to the end. Historic jewels taken in a few minutes. Then silence. In December 2022 much of the loot was returned as part of a negotiation with the defendants’ lawyers. In January 2023 four of them confessed. Between 16 and 17 May 2023 five members of the same clan were sentenced, with reduced terms precisely because of that deal. The loot worked like a decryption key: it went back to the rightful owner, traded for a lighter sentence.
And time, in this game, works for whoever holds the hostage. The theft at the Chácara do Céu museum in Rio de Janeiro, which took place in 2006 during Carnival, ended with the statute of limitations expiring and the works never recovered. Overall, according to Clopés and Balcells, full recovery happens in 44.7% of cases, partial recovery in 15.8%, and in 39.5% nothing is recovered.
A methodological note, in the open
This piece rests on few cases. The museum thefts for which I found a documented duration number seven. That is too small a number for any statistical test, and indeed I ran none: no percentage in this article is computed on my own sample. The percentages all come from Clopés and Balcells, and I’ve attributed them. The rest is a structured comparison between cases, not an inference.
The durations themselves are not all of the same quality, and I preferred to say so rather than level them out. Some are timed (Oslo, the fifty seconds of The Scream). Some are reconstructed from entry and exit times (Gardner, Villena, Louvre). Some are windows estimated by the police (Bode, about twenty-five minutes). The Munch 2004 figure, “under five minutes,” comes from a single source and I’ve flagged it as such. A case with only an estimated duration is not on a par with a timed one, and I’ve kept them distinct rather than pretending they were the same thing.
I did not use the material-type counts from the large police databases to talk about trends. The FBI’s National Stolen Art File, for example, removes an object once it is recovered. Anyone consulting that registry therefore sees mostly the cases that were never solved, and would draw distorted conclusions. In statistics this is called survivorship bias: you look only at what remains and mistake it for the whole.
One last piece of honesty, which applies even to the best source. Clopés and Balcells’s study, though peer-reviewed and open access, contains a few editorial inconsistencies: the security measures defeated per job are given as three in the body and four in the conclusions, the stolen pieces as seven and then as five, and the average value of the loot is printed with a unit typo. They don’t invalidate the work. They are the reason every fact here has a declared verification status. The same goes for the decline in cyber dwell time: in recent years the median is partly dragged down by ransomware, which announces itself and is therefore “detected” at once. The decline is real; it should be read with that caveat.
Where the analogy breaks, and what to do about it
Every analogy breaks somewhere. This one breaks at the point that matters most.
Information security can afford a low dwell time because, in the end, data has a backup. A file encrypted by ransomware is restored from a copy. A compromised system is reinstalled. Cyber defense plays a game in which restoration is possible, and that changes the calculation of every risk.
An artifact melted into ingots has no backup. A destroyed painting is not reinstalled. Cultural heritage is the one case in which failure is irreversible. Here the reference discipline becomes the safety engineering of physical plants, the kind that designs against failures that can’t be undone, where cyber defense was enough on its own.
From this comes the operational conclusion, and it runs against the instinct of anyone who buys security systems. Detection, in museums, has already won: the alarms sound almost every time, and the cases above confirm it one by one. Continuing to invest in eyes, sensors and cameras means optimizing the part of the problem that is already solved. It won’t shorten Villena’s four minutes, because those four minutes are shorter than the minimum time of any human response.
The only variable you can still act on is the other one: extraction time. Display cases that open in minutes and not in seconds. Anchors that have to be cut, not lifted. Physical delay engineered to stretch the job beyond the response time, instead of hoping the response arrives first. If the defender can’t run faster, they have to force the attacker to run longer.
Museums don’t have an alarm problem. They have a race condition. And a race condition isn’t won by watching more closely. It’s won by slowing down the other process.