📣 Send us your press release
Site updates every 15 minutes
Professional Services

LMU Munich Data Breach Affects Records of 600,000 Students

Ludwig-Maximilians-Universität München (LMU) has detailed the scope of a cyber incident affecting its IT systems since September 16. A student registration system, potentially holding records for 600,000 individuals, is believed to have been compromised.

30 September 2026
LMU Munich Data Breach Affects Records of 600,000 Students

Ludwig-Maximilians-Universität München (LMU) has provided an update on the extent of a data breach that targeted its IT systems, initially detected on September 16. The university's central registration system, which processes data for current and former students, is now confirmed to have been affected.

LMU has been working with internal and external IT security experts to investigate the attack. The affected system was taken offline immediately, and data was secured. Other, non-affected systems were also temporarily disabled for security checks. Supervisory and investigative authorities have been informed.

Forensic analysis indicates that the entire dataset within the registration system, containing records potentially going back 50 years, was impacted. Approximately 600,000 student records are believed to be involved. The types of data vary, with older records (up to 1994) containing primarily basic biographical and semester history information. More recent records (from 2005 onwards) may include additional details, such as bank information, where provided. LMU has stated that passwords, sensitive data in large quantities, and examination results remain unaffected.

The university has begun a phased restoration of non-affected IT systems. The central online course catalog (LSF) is scheduled to be fully accessible by September 30, 2026. Examination and feedback systems EvaSys and EvaExam are already back online. LMU is also continuing the rollout of its new cloud-based CampusOnline system for digital applications and enrollments.

LMU is actively monitoring the dark web for any signs of data publication or misuse, but currently reports no indications of such activity. The university advises affected individuals to remain vigilant and follow standard cybersecurity precautions, such as exercising caution with unsolicited links and attachments.

Original source: lmu.de