News

Questions about the data security incident

19 Sept 2026

Here is an overview of the latest information.

What happened?

An unauthorized actor gained access to standing data relating to student registrations stored in an LMU IT system. Currently, we must assume that these data were in fact retrieved. We have been able to prevent any modification or other manipulation of the data, and the data continue to be available to LMU. The technical and forensic investigation into the attack, conducted in close cooperation with the Bavarian State Criminal Police Office, is still ongoing.

When was the incident detected? How long did the incident last?

The incident was identified on 16.09.2026. Immediately upon detecting the first signs of unauthorized activity, we took countermeasures and shut down the affected system. We currently cannot provide any definitive information as to when the unauthorized attack began and how long it lasted.

What data was affected?

The following categories of data were affected, insofar as the relevant information was provided in the course of registration: identifying data (name, date of birth, gender, and (in some cases) place or country of birth); contact details (term-time and home address, (in some cases) phone number, LMU email address, and (in some cases) further email addresses); and bank details (e.g., IBAN, name of account holder). Health insurance numbers may also be affected. BAföG numbers and data relating to students’ course of study could be affected, along with information concerning previous school and academic qualifications. In individual cases, data that are relevant to reasons for leaves of absence and, in this respect, fall under Article 9 of the GDPR, may also be affected. Information relating to examinations at LMU, as well as specific information concerning course content and individual academic performance, is expressly not affected.

How many people and datasets are affected? What time period does the data cover?

The technical investigation is still ongoing. At this time, we cannot provide reliable estimates of the total number of people, data volume, or periods affected.

What actions did LMU take after detecting the incident?

Immediately after the first indications of the incident, LMU took highly comprehensive countermeasures and removed the affected component from the system. Since then, LMU has been working with the competent law-enforcement authorities and with external specialists, including on defending our systems from further attacks. In addition to the enrollment server affected by the incident, we also took certain unaffected systems offline as a precaution. As a result, some internal services are temporarily unavailable. We are analyzing the affected datasets and have initiated an expansion of security monitoring and a technical and organizational hardening of the affected IT systems. In addition, qualified specialists are monitoring whether signs of the affected data show up in relevant portals on the so-called darknet.

Have the data been published, or are there any indications of misuse?

Based on the information currently available, we have no indications that the attacker has published the dataset obtained, intends to do so, or has otherwise misused the data. If our enhanced monitoring or the ongoing investigation reveals any evidence that the data has been published or otherwise misused, we will notify the affected individuals without delay.

What effects does the incident have on teaching/studies and registration?

Teaching and studies are unaffected. Registration will resume as of this coming week after a brief interruption. Affected registration deadlines will be extended accordingly, so that students are not put at any disadvantage in their studies. Existing registrations will remain perfectly valid as before.

Are other systems affected by the incident?

In the course of our security protocol, we shut down various unaffected systems as a precaution in addition to the registration server affected by the incident. This has caused some internal services to be temporarily unavailable.

The following answers are intended primarily for applicants and other individuals whose data were processed in the affected system.

Are my data affected?

Analysis of the data is still ongoing. As soon as we know more, we will inform the people affected.

There are currently no indications that data from the attack has been published or otherwise misused. Should the additional monitoring put in place by LMU or the ongoing investigation reveal any such indications, we will notify those affected without delay. As a precaution, however, we recommend that people be especially vigilant and observe the general data security guidelines.

What should I do now?

Although there is currently no reason to assume that the attacker intends to misuse the data, we advise you to remain particularly vigilant and follow standard security precautions. For your own protection, please observe the following in particular:

  • Do not open any attachments or links, even in emails that seem to be addressed to you personally – whether from known or unknown senders – without carefully inspecting them first.

  • Be very wary of suspicious approaches by email, telephone, or text message, especially ones that make reference to LMU or your studies. Specifically, do not reveal any bank details or passwords.

  • Be particularly on your guard if you receive documents or messages that make reference to LMU or your studies.

  • You can find further information about how to protect yourself against fraudsters on the website of the German Federal Office for Information Security: https://www.bsi.bund.de.

Should I change passwords and bank details?

As general advice, we recommend being highly vigilant and observing the abovementioned general data security guidelines.

Do I have to repeat the registration process?

New registrations that were completed before the portal was shut down were securely stored. You do not have to register again.

When are registrations open again? What about the deadlines?

Teaching and studies are unaffected. Registration will resume as of this coming week after a brief interruption. Affected registration deadlines will be extended accordingly, so that students do not suffer any impediments to their learning. Existing registrations will remain perfectly valid as before.

Where can I turn if I have further questions?

For any questions, please contact: cybersicherheit@lmu.de

What are you looking for?