Opens in a new tab

Hackers access LMU student data in cyberattack

Sunday 20th September 2026 on 11:15 in Bavaria

cyberattack, data security, LMU Munich

Hackers have accessed personal data belonging to students at Ludwig Maximilian University of Munich, BR reported. The university said contact details, bank information and other registration data may be affected, but the full extent of the incident remains unclear.

Cybercriminals penetrated the university’s IT systems shortly before the start of the new winter semester, according to a statement published on the university’s website. They accessed students’ personal data connected with enrolment at LMU.

The information includes names, dates and places of birth, gender, addresses, telephone numbers, email addresses and bank details such as IBANs and account holders’ names. Health insurance information, BAföG numbers, study history and details of previous school or university qualifications were also affected.

Examination information, specific details about courses and individual academic performance were not affected, the university said. It also said it had prevented any alteration or other manipulation of the data.

The university identified the incident on Wednesday and immediately took countermeasures, including shutting down the affected system. The timing of the intrusion and how long the attackers had access are not known.

Technical investigations are continuing, so LMU cannot yet provide reliable figures on the number of people affected, the volume of data involved or the periods covered. The university is working with investigative and supervisory authorities as well as external specialists to investigate the incident and prevent further attacks.

It also remains unclear whether the data were stolen. Specialists are monitoring relevant dark web portals for signs that the information has been published. LMU said there was currently no indication that the attacker had published, intended to publish or otherwise misused the data. Affected people would be contacted immediately if such evidence emerged.

Several systems were taken offline as a precaution, temporarily making some internal services unavailable. The university said teaching and study operations were not expected to be affected. Enrolment is scheduled to resume next week after a brief interruption, and affected deadlines will be extended. Existing enrolments remain valid.

LMU advised students not to open attachments in suspicious emails and not to disclose bank details or passwords. The university is publishing updates on its website.

Source 
(via BR)