LMU München: Datenleck betrifft 600.000 Studierende und reicht 50 Jahre zurück

LMU Munich: Data Breach Affects 600,000 Students Dating Back 50 Years

Following a cyberattack on Ludwig-Maximilians-Universität München (LMU) two weeks ago, the university has released new details regarding the extent of the security incident. A total of roughly 600,000 records belonging to current and former students are affected, with enrollment records dating back as far as 50 years.

What Data Was Stolen

As the university stated in its updated notice on the data protection incident, the attackers exfiltrated master and enrollment data. For a portion of individuals recorded since 2005, banking details were also compromised, as initial reports on the Datenleck an der LMU München had previously suggested.

In individual cases, the compromised data includes further personal information submitted during enrollment. This includes health insurance and BAföG (student financial aid) numbers, as well as details on academic history and previous degrees. Stated reasons for leaves of absence may also be affected, potentially containing special category health or personal data under Article 9 of the General Data Protection Regulation (GDPR). The university emphasizes that not all categories of data were leaked for every affected individual.

Grades and Examination Data Remain Secure

According to LMU, critical areas of academic administration remained protected from unauthorized access. Examination information, grades, and specific records of completed academic coursework were not among the stolen data.

See also  Citrix NetScaler Under Attack: CISA Flags Exploited Authentication Bypass (CVE-2026-19490)

The university currently has no evidence that the data has been published on the internet. However, according to LMU, subsequent misuse by third parties cannot be ruled out.

Restricted System Access and Security Advice

The IT systems isolated following the attack are being gradually brought back online. Enrollments have been possible again since last week. The university’s campus management system, LSF (“Lehre, Studium, Forschung”), is available again as of this Wednesday afternoon around 3:00 PM—albeit with access restrictions for now.

Direct access via the public internet remains blocked. Students can access the system on campus via the university Wi-Fi in the Munich Science Network (MWN) or through the LMU administrative network. Remote access strictly requires an encrypted network connection, for which the university points to eduVPN to connect to the MWN.

Because bank details may have been leaked, current and former LMU students should monitor their account activity for suspicious transactions and remain vigilant against fraud and phishing attempts in incoming communications.

Sources: Heise – News

Leave a Comment

Your email address will not be published. Required fields are marked *

Mastodon
Scroll to Top