Information about a personal data breach
19 Sept 2026
LMU has become the target of an attack on its IT systems. In accordance with Article 34 of the GDPR, the University Executive Board provides information on the details known to date.
19 Sept 2026
LMU has become the target of an attack on its IT systems. In accordance with Article 34 of the GDPR, the University Executive Board provides information on the details known to date.
An unauthorized actor gained access to standing data relating to student registrations stored in an LMU IT system. Currently, we must assume that these data were in fact retrieved. We have been able to prevent any modification or other manipulation of the data, and the data continue to be available to LMU. The technical and forensic investigation into the attack, conducted in close cooperation with the Bavarian State Criminal Police Office, is still ongoing.
The following data categories are affected, insofar as such information was provided in the course of registration: identifying data (name, date of birth, gender, and (in some cases) place or country of birth); contact details (term-time and home address, (in some cases) phone number, LMU email address, and (in some cases) further email addresses); and bank details (e.g., IBAN, name of account holder). Health insurance numbers may also be affected. BAföG numbers and data relating to students’ course of study could be affected, along with information concerning previous school and academic qualifications. In individual cases, data that are relevant to reasons for leaves of absence and, in this respect, fall under Article 9 of the GDPR, may also be affected. Information relating to examinations at LMU, as well as specific information concerning course content and individual academic performance, is expressly not affected.
Based on the information currently available, we have no indications that the attacker has published the obtained dataset, intends to do so, or has otherwise misused the data.
Immediately after the first indications of the incident, LMU took extensive countermeasures and removed the affected component from the system. Since then, we have been working with the competent law-enforcement authorities and with external specialists, also to defend our systems against further attacks. There has been no disruption to teaching or studies, and registration will resume this coming week after a short interruption. This will not put you at any disadvantage in your studies, and the affected registration deadlines will be extended accordingly.
Here are some of the specific actions LMU has undertaken:
In particular, qualified specialists are monitoring relevant portals on the so-called dark web for indications relating to the affected data.
If this monitoring and the ongoing investigation reveal indications that data have been published or otherwise misused, we will notify you without delay.
Although we currently have no reason to assume that the attacker intends to misuse the data, we advise potentially affected individuals to be particularly vigilant. We also recommend taking the usual general precautions. For your own protection, please pay particular attention to the following:
If you have any questions, you can contact us at any time at: cybersicherheit@lmu.de.