Update on the persona data breach
28 Sept 2026
LMU has become the target of an attack on its IT systems. In accordance with Article 34 of the GDPR, the University Executive Board provides information on the details known to date.
28 Sept 2026
LMU has become the target of an attack on its IT systems. In accordance with Article 34 of the GDPR, the University Executive Board provides information on the details known to date.
Since 16 September, LMU has been devoting the maximum of its time and personnel resources, to defend against and investigate the unauthorised cyberattack on one of its IT systems. Immediately after the first indications of the incident, LMU took extensive countermeasures. and removed the affected component from the system. The affected IT system was shut down, and the data were secured. As a precautionary measure, further unaffected systems were taken offline and subjected to security checks. The competent supervisory and investigating authorities were informed, and a comprehensive analysis of the incident was launched without delay with the support of internal and external IT security experts.
According to the latest forensic findings, it has now been established that the entire data set in the admissions system was affected, i.e. the system in which all data relating to current and former students are processed. The records held there therefore include enrollment data going back approximately 50 years. Approximately 600,000 data sets are assumed to be affected.
The affected categories vary considerably, and their scope steadily decreases depending on the age of the data. Accordingly, data records up to and including 1994 contain only standing data and semester history; from 2005 onwards, more extensive information is available, including, in some cases, bank details. Otherwise, the analysis results have confirmed the categories of affected data already communicated on 19 September. These include identity, contact and bank details, where such information was provided, as well as, depending on the individual case, further information on the course of study and reasons for leave of absence.
Passwords, sensitive data on a larger scale, and LMU examination information or specific information on course content and individual academic performance continue to be expressly unaffected.
As a public institution, LMU is required to process certain study-related information on a long-term basis in order to perform its public functions and in accordance with information responsibilities of public administration. The data are required, for example, as evidence for the statutory pension insurance scheme or to determine university semesters. In many cases, LMU makes the data available to former and current students only shortly before they reach retirement age. For the long-term storage of these data, LMU follows the retention period of approximately 50 years customary in higher education. The indication of a retention period of “up to” 100 years in the general data protection information for students on our website did not apply and was misleading in this context; the information has since been clarified.
With professional external support and assistance from the relevant authorities, LMU continues to focus not only on investigating the incident but also on closely monitoring the darknet in order, where possible, to determine whether the data have been published. Based on the findings to date, there continue to be no indications of either publication or any other misuse of the data.
LMU will gradually restore individual systems that were not affected by the data security incident but were shut down as a precaution, following comprehensive IT security checks. The central online course catalogue (LSF) of Ludwig Maximilian University of Munich (LMU) will be accessible again on Wednesday, 30 September 2026, from 9:00 a.m. for programme coordinators and from 3:00 p.m. for students.
Initially, the most important functions for the start of the semester will be available: courses can be amended and registered for, and grade reports can be accessed. Any missing grade entries will be added promptly. Further LSF functions will be introduced gradually after 30 September.
For security reasons, access to LSF will initially be possible only via the Munich Research Network (MWN) and the LMU administrative network. Outside LMU, a VPN connection is required. Please use Edu-VPN for the Munich Research Network; information is available at www.lmu.de/vpn.
The EvaSys and EvaExam systems for feedback and examination processes will again be available in both networks from Monday, 28 September 2026, at 12:00 noon. The IT security checks of OpenCampus and Apte (including aptitude assessment procedures) are ongoing. LMU will provide information on their restoration as soon as possible.
In parallel, the ongoing introduction of the planned new CampusOnline system is being emphatically pursued. From December 2026, it will enable digital applications and enrolments throughout the university on a secure cloud-based platform.
There continue to be no indications that data from the attack have been published or otherwise misused. Should the additionally established monitoring or the ongoing investigation reveal any such indications, we will inform the affected individuals without delay. We advise particular vigilance and recommend the standard security precautions. In particular, the following should be observed for your own protection:
All further updates on the incident and on the renewed availability of individual services will be published on an ongoing basis here in the Newsroom FAQs .
Affected individuals may contact cybersicherheit@lmu.de at any time with questions.