Opens in a new tab

LMU hack raises fears over students’ sensitive data

Monday 21st September 2026 on 17:45 in Bavaria

cybersecurity, identity theft, LMU

Students at Ludwig Maximilian University of Munich are concerned that hackers may have accessed sensitive personal information, BR reported. Experts warn of a risk of identity theft and advise affected people to monitor their bank accounts and email inboxes closely.

The stolen data could include names, dates of birth, addresses, bank account details and possibly health insurance numbers. The university said many details remained unclear, including exactly which information the hackers accessed and how many students may be affected.

The LMU learned of the incident on Wednesday and informed students by email. It warned them to be particularly cautious with unfamiliar messages and not to click on links. Some students said the general information had not made clear whether they were affected or what steps they should take.

“I’m worried,” LMU student Ha My said. Student Beeke said she still did not know whether she was affected or what the consequences would be. Another student, Kristina, questioned whether she needed to change her passwords.

IT security adviser Manuel Atug said there was little that people could do immediately beyond carefully checking their accounts. He advised them to look for unusual activity in their bank accounts and to examine emails for signs that someone was trying to manipulate them or confirm orders.

Identity theft was the greatest risk in such attacks, Atug said. Criminals could use stolen identities to apply for credit cards, order goods from online retailers, open accounts or conclude other contracts in the victims’ names, said Ann-Kathrin Edinger of the Verbraucherzentrale Bayern, a consumer advice centre.

The Verbraucherzentrale Nordrhein-Westfalen offers a tool that people can use to check whether their personal data has been misused. Edinger also warned about phishing messages and advised caution with links and attachments.

LMU said passwords and university login details had not been affected. The university nevertheless recommends changing passwords regularly, independently of the incident.

The breach is particularly serious because the affected student records contain information submitted during enrolment. In addition to names and email addresses, these records may include addresses, telephone numbers, bank details, health insurance numbers and information about students’ previous academic records.

The University of Applied Sciences Munich was also hacked at the end of July, a spokesperson confirmed to BR24. Information relating to around 400 people who had applied for a degree programme was affected, in most cases names and email addresses.

The Central Office for Cybercrime Bavaria and the Bavarian State Criminal Police Office have taken over the investigation.

Source 
(via BR)