LMU Munich student data breach (2026): what was exposed and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
What happened
Ludwig-Maximilians-Universität München (LMU Munich) reported on September 19, 2026 that it was the target of an attack on its IT systems. In a GDPR Article 34 notice, the University Executive Board said an unauthorized actor gained access to standing student-registration data stored in an LMU IT system, and that LMU must currently assume those data were retrieved.
LMU said it prevented modification or other manipulation of the data, and that the data remain available to the university. The technical and forensic investigation is ongoing in close cooperation with the Bavarian State Criminal Police Office (Bayerisches Landeskriminalamt).
In its FAQ, LMU said the incident was identified on September 16, 2026. It shut down the affected system after the first signs of unauthorized activity. LMU said it cannot yet give definitive information on when the unauthorized access began or how long it lasted.
LMU has not published an official count of affected students. Do not invent a headcount from enrollment totals reported elsewhere.
Based on information available at the time of its notice, LMU said it had no indications that the attacker had published the dataset, intended to publish it, or otherwise misused the data. It said teaching and studies were not disrupted, and that registration would resume after a short interruption with extended deadlines so students are not disadvantaged. LMU’s FAQ later noted enrollment resumed September 22, 2026 after the system was rebuilt.
Sources
- Information about a personal data breach – LMU Munich (Sep 19, 2026)
- Questions about the data security incident – LMU Munich (Sep 19, 2026)
What data was exposed
Per LMU’s official notice and FAQ, the following categories may be affected insofar as the information was provided during registration (not every field for every student):
- Identifying data: name, date of birth, gender, and (in some cases) place or country of birth
- Contact details: term-time and home address, (in some cases) phone number, LMU email address, and (in some cases) further email addresses
- Bank details: e.g. IBAN and name of account holder
- Health insurance numbers (may also be affected)
- BAföG numbers and data relating to students’ course of study
- Information concerning previous school and academic qualifications
- In individual cases, data relevant to reasons for leaves of absence that fall under Article 9 GDPR
Expressly not affected (per LMU): information relating to examinations at LMU; specific information concerning course content and individual academic performance; and (FAQ update Sep 20) passwords and LMU user IDs.
Breach details
| Detail | Value |
|---|---|
| Breach name | LMU Munich (student registration standing data) |
| Date | Identified September 16, 2026; unauthorized access window not yet finally determined |
| Disclosed | September 19, 2026 (GDPR Art. 34 notice + FAQ) |
| Accounts affected | Not disclosed by LMU (do not invent a count) |
| Domain | lmu.de |
This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your personal data is involved, contact our support team.
We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by LMU Munich; it reflects a publicly reported security incident.
For whether your personal data was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you), not this page alone.
What to do now
Based on the data exposed in this breach, here are the steps you should take:
- Watch for further notices from LMU (including to your LMU email). Questions: cybersicherheit@lmu.de (per LMU).
- Treat unexpected emails, calls, or messages that cite LMU, your studies, BAföG, or enrollment as possible phishing. Do not open attachments or follow links without careful inspection; do not disclose bank details or passwords.
- If your IBAN / account-holder name may have been involved, monitor bank accounts for unexpected direct debits or social-engineering attempts that reference those details.
- Prefer official contacts from lmu.de notices over numbers or links in unsolicited messages.
- Review German Federal Office for Information Security (BSI) guidance on fraud and passwords if you want general hardening steps: https://www.bsi.bund.de
- Academic performance and exam records were not part of this incident per LMU — be skeptical of messages that claim “your grades were leaked.”
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
- What to do after a data breach
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.