Overview
- The intrusion was discovered on Wednesday, September 16, and the university immediately took the affected enrollment system offline to stop further access.
- LMU says attackers copied enrollment master data that can include names, birth dates, addresses, phone numbers, email addresses, IBANs and other bank details, plus possible health insurance and BAföG numbers.
- Police and external IT forensics teams are examining logs and systems to establish how long the intruder had access and exactly which records were taken.
- The university has isolated some internal services, plans to resume enrollments with extended deadlines, and is warning students to watch for phishing and fraud attempts while it notifies anyone proven affected.
- No public release or confirmed misuse of the stolen data has been found so far, but the scale is unclear and the case could trigger regulatory scrutiny under EU data rules and increased risk of identity and financial fraud for students.