Ransomware victim disclosure
← All victimsNationalmuseet (National Museum of Denmark)
listed as National Museum · Claimed by Thegentlemen · listed 7 hours ago
Status timeline
- ListedJun 15, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Denmark
- Sector
- Public Sector
- Listed on leak site
- Jun 15, 2026
About the victim
AI dossier — public-source company profileNationalmuseet is Denmark's premier national museum located in Copenhagen, dedicated to preserving and presenting Danish cultural history and global ethnographic collections. It houses significant archaeological treasures including Viking artifacts and the Sun Chariot, and operates multiple museum locations across Denmark.
- Industry
- Museums & Cultural Heritage
- Address
- Ny Vestergade 10, Prinsens Palæ, DK-1471 København K, Denmark
Attack summary
Severity: low — The leak post contains only a generic description of the museum with no evidence of proof files, screenshots, or specifics about what data was actually compromised or published. No operational disruption is claimed.The threat actor claims to have compromised Nationalmuseet and published data. The leak post provides no specific details on the nature of data exfiltrated, encryption status, or operational impact.
What the group claims
***.dk zoominfo.com/c/national-museum/372526094 The National Museum of Denmark, located in the heart of Copenhagen, is the country's premier institution for cultural history, spanning from the Stone Age to the present day. It houses world-renowned archaeological treasures—including Viking hoards, the ancient Sun Chariot, and the Egtved Girl—alongside extensive global ethnographic collections. The museum is dedicated to exploring and sharing Denmark's rich heritage and global human history through engaging, research-driven exhibitions
Sources
- Victim sitenatmus.dk
Source
Indexed 7 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

