Ludwig Maximilian University of Munich (LMU) is dealing with the aftermath of a break-in into its IT systems that copied the personal data of its students. In a statement, the university said "master data on enrollments" was taken — the complete records used for matriculation, including names, dates of birth, addresses and email addresses. Bank details such as IBAN and account holder, BAföG student-aid numbers and health-insurance information may also have leaked. LMU did not say how many people were affected; roughly 53,000 are currently enrolled.
According to the Bavarian public broadcaster BR, the attack was discovered on Wednesday of this week. The university took the affected systems offline and isolated them, expanded security monitoring and started forensic work; BR reports that the Bavarian state criminal police office has also opened an investigation. How the attackers got in, and how long they were inside, is not yet known.
The university says there is so far no indication that the attacker has published the stolen data set, intends to publish it, or has misused it in any other way, and that specialists are watching relevant darknet portals. There are no signs of a classic ransomware attack.
Enrollment for the winter semester that starts on 12 October is to resume shortly, with deadlines extended. LMU stresses that students will not suffer any disadvantage to their studies, while advising heightened vigilance — particularly towards contact that claims to be about their studies. With near-complete identity records in criminal hands, targeted phishing and identity fraud are considered a real risk.
Critics noted the awkwardness of the university's advice that students should not disclose bank data or passwords, given that it appears to have been unable to protect exactly that information itself. German universities have become a recurring target: the case lands amid a broader wave of attacks on public institutions and municipalities in the country.



