“An unknown perpetrator succeeded in gaining access to basic data stored in one of the university’s IT systems. We must currently assume that this data was also copied,” university representatives said.
LMU is one of the largest universities in Germany: in the 2025/26 winter semester, more than 52,000 students were registered there.
The attack took place on 16 September. According to LMU, the affected system was shut down immediately after the first signs of a breach. How long the perpetrator had access is not yet known. The information in question is that which students provided at matriculation, that is, upon admission to the university.
The Breach Affected Identification Data
Three categories of information are at risk:
- identification data (name, date of birth, gender and, where applicable, place or country of birth);
- contact data (term-time address and home address, telephone number where applicable, university and personal email addresses);
- bank data (IBAN, account holder’s name).
In addition, the hackers may have obtained health insurance numbers, BAföG recipient numbers and details of previous school education. “The attack did not affect LMU examination information, nor specific data on the content of studies or individual academic performance,” university representatives clarified. The university assured students that the affected individuals will not encounter problems with their studies.
The Number of Affected Students Has Not Yet Been Established
The exact number of those affected and the volume of compromised data are currently being determined; there are no specific figures. It is also not yet clear whether the attack affected only current students or also university graduates. The university is working closely with investigating authorities and external cybersecurity specialists, and the case is being investigated by the Bavarian State Criminal Police Office. Digital forensics specialists have also been engaged to search for traces of the perpetrator.
Some systems that were not affected by the attack were taken offline as a precaution, so certain services are temporarily unavailable. The university added: “We are analysing the affected data sets and have already begun expanding our security monitoring system, as well as strengthening the technical and organisational protection of the affected IT systems. In addition, specialists are monitoring whether signs of a leak of this data appear on the relevant platforms in the so-called darknet.” The darknet is the part of the internet that cannot be accessed through an ordinary browser and where criminals often publish stolen data sets. So far, the stolen data has not been published.
The Academic Process Has Not Been Affected
According to LMU, there are as yet no signs that the hacker has published the stolen data or intends to do so. Those affected will be notified if the situation changes or if the data is used in any other unlawful manner. Such information is often used for identity theft: attempts are made to carry out fraudulent banking transactions or online orders with it. A combination of name, address, date of birth and account details can make it easier for fraudsters to approach a person convincingly, posing as employees of a bank or other organisations, with a view to subsequent fraudulent activity.
The academic process has not been disrupted, and matriculation resumes today, 21 September. The university recommends that new students and applicants not open attachments and links in emails without careful checking. Particular caution should be exercised with suspicious attempts to make contact by email, telephone or messages, “especially if they mention LMU or your studies”.
Additional advice on protection against fraud has been published by Germany’s Federal Office for Information Security on its website https://www.bsi.bund.de. Those who managed to complete matriculation in full before the portal was taken offline do not need to do anything; their data has already been saved in the system.
The upshot for today is as follows: the data appears to have been copied but has not been published on the darknet, the number of those affected is unknown, and the investigation continues. Those affected will be notified if the situation changes.


