An unidentified attacker has gained unauthorized access to sensitive data belonging to students at the Ludwig-Maximilians-Universität (LMU) in Munich. As the university announced over the weekend, an IT system responsible for managing enrollment master data was compromised.
According to current findings, the perpetrator managed to exfiltrate extensive datasets. These include students’ full names, postal and email addresses, places of birth, and stored bank details. In addition, the attacker accessed further private records, including information on previous educational qualifications. It remains unclear exactly how many individuals are affected and whether the breach involves only current or also former students. In the recent winter semester of 2025/26, LMU enrolled more than 52,000 students, making it one of the largest universities in Germany.
Criticism Over Delayed Notification
According to the university, the security incident was discovered on the preceding Wednesday. However, the official statement on the university website was not published until the following Saturday. This delay drew immediate political criticism. Florian von Brunn, digital affairs expert for the SPD state parliamentary group, pointed to the requirements of the General Data Protection Regulation (GDPR), which mandates notifying affected individuals without undue delay. He demanded a full investigation into when the unauthorized access began, how long it persisted, and which vulnerabilities were exploited.
The incident is reminiscent of similar attacks in the public sector. For instance, the recent cyberattack on Berlin’s state network illustrated how far-reaching the consequences of compromised administrative data can be.
LKA Investigation and Status of the Data
The Bavarian State Criminal Police Office (LKA) has been brought in to investigate the case. Together with external IT forensics experts, LMU is working to fend off further attacks and close the security loophole. The specialists are also monitoring the darknet—a segment of the internet inaccessible via conventional web browsers and frequently used by criminals to trade stolen datasets. So far, the stolen records have not surfaced there.
The university emphasized that students will not suffer any academic disadvantages regarding their studies due to the incident. However, because criminals can exploit such personal records and bank details for fraudulent online purchases or identity theft, those affected should exercise increased caution in the coming weeks.
What Students Should Do Now
- Monitor bank activity: LMU students should closely check their bank accounts in the near future for unauthorized direct debits or suspicious transactions, and report any anomalies immediately to their bank to dispute the charges.
- Watch out for suspicious messages: Heightened vigilance is advised regarding unexpected emails, SMS messages, or phone calls. Attackers often leverage stolen personal details for targeted phishing attempts, masquerading as government agencies, banks, or university departments.
- Never disclose sensitive data: Requests to confirm passwords, TANs, or payment details should never be answered through links provided in messages.
Sources: FAZ.de














