One of Germany's premier institutions, Ludwig Maximilian University of Munich (LMU Munich), is examining a security breach in which attackers gained unauthorized access to a database holding confidential student records. The breach came to light on Saturday, with the university confirming that personal enrollment information stored on one of its systems had been compromised.
"Currently, we must assume that this data were in fact retrieved," the university said, noting that its investigation remains active. The institution, which serves more than 52,000 students and ranks among Germany's largest universities, stated it has found no evidence suggesting the compromised records were modified, erased, or made public.
The potentially compromised dataset encompasses a broad range of personal identifiers and sensitive details. Exposed information includes student names, birth dates and other identifying markers; contact information and institutional email addresses; banking details; and records pertaining to academic programs and prior educational background.
Additionally, the breach may have affected health insurance identification numbers and reference codes tied to Germany's student aid system. In certain instances, the compromised material could encompass documentation explaining why students took academic breaks, according to the university's statement.
Notably, exam records, course-specific content and individual student performance evaluations were not compromised. The university identified the intrusion on Wednesday but has not yet established when the unauthorized access commenced or its duration. The institution has also withheld details regarding the number of affected individuals and the scope of data extracted.
The perpetrator remains unidentified, and the university has not indicated whether a ransom request was made.
Systems taken offline
Upon discovering the breach, LMU Munich isolated the compromised server and engaged external cybersecurity experts to assist with containment. The institution is also collaborating with law enforcement authorities on the investigation.
As a protective measure, several unaffected systems were also taken offline, temporarily disrupting certain internal operations. While the attack did not interrupt academic instruction, enrollment processing was halted temporarily and is anticipated to resume within the week. LMU Munich has pledged to extend affected enrollment deadlines to ensure students face no disadvantage.
The university has tasked specialists with monitoring dark-web marketplaces and comparable venues to detect any circulation of the stolen information. Some students have already encountered difficulties accessing university platforms needed for semester preparation.
"I can't register for courses, I can't view my grades," one student told German regional news outlet Rosenheim24.
Academic institutions have emerged as prime targets for cybercriminals due to their networks' capacity to store extensive volumes of personal and financial data while serving diverse populations encompassing students, faculty and administrative personnel.
Recent ransomware incidents affecting American universities include attacks on the University of Texas, the University of Oklahoma, Stanford University and the University of Michigan, with several occurring following holiday periods. The University of Pennsylvania experienced email system disruption during a cybersecurity incident in October, while Columbia and Harvard universities both endured attacks in the previous year.



