Information über einen Datenschutzvorfall - LMU München

· Original article ↗

Summary

LMU München reported that an unauthorized attacker accessed an IT system containing student enrollment master data. The university considers it possible that the data was retrieved, but says there is currently no indication that it has been published or misused. The affected server was isolated, and forensic investigation is ongoing.

Key points

  • The incident was reported on 2026-09-19; the date of the attack was not disclosed.
  • An unauthorized attacker accessed enrollment master data stored in an LMU IT system. The university assumes the data may also have been retrieved.
  • Potentially affected data includes identifying and contact details, bank information, health insurance numbers, BAföG numbers, study-course information, and previous school or university qualifications. Some individual cases may include data concerning leave-of-absence reasons.
  • The university said examination information and details of study content or individual performance were not affected.
  • LMU said there was no indication that the attacker had published the data, intended to do so, or otherwise misused it.
  • LMU isolated the affected server, engaged forensic and security specialists and authorities, expanded monitoring, and is hardening affected systems. The investigation is ongoing.
  • The university reported no disruption to study operations; enrollment had a short interruption. No ransom or extortion activity was reported.

Tags

Cyber AttackData BreachPersonal Data ExposureHigher Education

Countries

Industries