Data Breach at Ludwig-Maximilians-Universität München IT Systems
Ludwig-Maximilians-Universität München (LMU) has experienced a data breach affecting student registration data. An unauthorized party accessed and potentially downloaded personal information from an LMU IT system.

Ludwig-Maximilians-Universität München (LMU) has reported a data security incident involving unauthorized access to its IT systems. An external attacker gained access to personal data stored for student registrations, with the possibility that this data was also downloaded. The university stated that the data was not altered or manipulated, and remains available within LMU's systems.
The breach affected various categories of personal information collected during student registration, provided the data was submitted by the student. This includes identifying details (name, date of birth, gender, place/country of birth), contact information (semester and home addresses, phone numbers, LMU email and other email addresses), and banking details such as IBAN and account holder name. Health insurance numbers, BAföG (student loan) numbers, and details regarding academic progress and prior educational qualifications may also be compromised. LMU explicitly stated that examination information or specific details about course content and individual performance were not affected.
LMU is conducting a comprehensive investigation in collaboration with law enforcement agencies and external IT forensics specialists. The affected server component has been isolated from the network, and measures are being implemented to enhance system security and prevent further attacks. Student operations have not been significantly impacted; registration will resume after a brief interruption, and relevant deadlines will be extended. Currently, there are no indications that the accessed data has been published or misused by the attacker.
The university advises affected individuals to exercise caution, particularly regarding unsolicited emails or contact attempts, and to avoid opening attachments or clicking links without verification. Students are encouraged to protect their personal information and be vigilant against potential phishing or fraud attempts. LMU is actively monitoring for any signs of data publication or misuse and will provide further updates. Comprehensive FAQs and contact information are available on the LMU website.