Full Report
Einem unbefugten Angreifer ist es gelungen, auf in einem IT-System der LMU gespeicherte Stammdaten zu Immatrikulationen zuzugreifen. Derzeit müssen wir davon ausgehen, dass diese Daten auch abgerufen wurden. Eine Veränderung oder sonstige Manipulation der Daten konnte verhindert werden; die Daten stehen bei der LMU weiterhin zur Verfügung. Die abschließende technische und forensische Aufklärung des Angriffs in enger Zusammenarbeit mit dem Landeskriminalamt dauert noch an. Folgende Datenkategorien sind betroffen, soweit im Rahmen der Immatrikulation entsprechende Angaben gemacht wurden: Identifizierende Daten (Name, Geburtsdatum, Geschlecht, ggf. Geburtsort oder -land), Kontaktdaten (Semester- und Heimanschrift, ggf. Telefonnummer, LMU-E-Mail-Adresse und ggf. weitere E-Mail-Adresse) sowie Bankdaten (z.B. IBAN, Name des Kontoinhabers). Grundsätzlich möglich ist auch eine Betroffenheit der Krankenversicherungsnummer. Daneben können BAföG-Nummern und Daten im Hinblick auf den Studienverlauf betroffen sein sowie Angaben zu vorigen Schul- oder Studienabschlüssen. Im Einzelfall können Daten betroffen sein, die für Beurlaubungsgründe relevant sind und insoweit unter Art. 9 DS-GVO fallen. Ausdrücklich nicht betroffen sind Prüfungsinformationen der LMU oder konkrete Angaben zu Studieninhalten und individuellen Leistungen.
Analysis Summary
# Incident Report: Unauthorized Access to LMU Enrollment Master Data
## Executive Summary
Ludwig Maximilian University of Munich (LMU) experienced a targeted cyberattack on its IT infrastructure resulting in unauthorized access to enrollment master data. While data integrity was maintained, forensic evidence suggests a significant volume of personal, financial, and sensitive academic data was likely exfiltrated. The university responded by isolating affected systems and collaborating with the State Criminal Police Office (LKA) to mitigate further risk.
## Incident Details
- **Discovery Date:** September 19, 2026 (Public disclosure date)
- **Incident Date:** Shortly preceding September 19, 2026
- **Affected Organization:** Ludwig Maximilian University of Munich (LMU)
- **Sector:** Education / Research
- **Geography:** Munich, Germany
## Timeline of Events
### Initial Access
- **Date/Time:** Undisclosed (Prior to Sept 19, 2026)
- **Vector:** Targeted attack on an IT system storing enrollment data.
- **Details:** An unauthorized actor bypassed security controls to gain access to a server containing student master records.
### Lateral Movement
- **Details:** Not explicitly detailed in the report; however, the attacker reached central databases housing enrollment and financial information.
### Data Exfiltration/Impact
- **Data Stolen:** The university assumes data was retrieved/exfiltrated. This includes:
- **Identity:** Name, DOB, gender, place of birth.
- **Contact:** Addresses, phone numbers, LMU and private emails.
- **Financial:** IBAN, account holder names.
- **Government/Sensitive:** Health insurance numbers, BAföG numbers (student loans), and Article 9 GDPR data (reasons for leave of absence).
- **Integrity:** No data manipulation or deletion occurred.
### Detection & Response
- **Discovery:** Identified via "first signs" of suspicious activity (likely monitoring alerts).
- **Response:**
- Immediate isolation of affected servers.
- Notification of data protection authorities (Art. 34 GDPR) and law enforcement.
- Brief suspension of the enrollment process.
- Engagement of external forensic experts.
## Attack Methodology
- **Initial Access:** Unauthorized access to IT systems (Specific vulnerability undisclosed).
- **Collection:** Automated or manual gathering of student enrollment databases.
- **Exfiltration:** Presumed exfiltration of master data records.
- **Impact:** Potential for identity theft, phishing, and financial fraud.
## Impact Assessment
- **Financial:** High potential risk for students due to leaked IBANs and identity data.
- **Data Breach:** Large-scale breach of personal and sensitive data (GDPR Art. 9 included).
- **Operational:** Temporary suspension of the enrollment process; no disruption to general teaching operations.
- **Reputational:** Significant, involving the leak of student private information.
## Indicators of Compromise
- **Network indicators:** Not disclosed in the public report.
- **File indicators:** Not disclosed in the public report.
- **Behavioral indicators:** Unusual access patterns to the enrollment database servers.
## Response Actions
- **Containment:** Affected server was immediately isolated from the network.
- **Eradication:** Forensic analysis conducted by external specialists and the LKA to ensure no persistence remains.
- **Recovery:** Technical and organizational hardening of IT systems; resumption of enrollment services with extended deadlines.
- **Monitoring:** Active "Darknet" monitoring to detect potential sale or publication of the stolen data.
## Lessons Learned
- **Key Takeaways:** Centralized databases of sensitive student data are high-value targets for attackers.
- **What could have been done better:** Earlier identification of the vulnerability before the exfiltration phase could have prevented the data breach.
## Recommendations
- **Identity Protection:** Monitor bank accounts for unauthorized transactions and be vigilant against targeted phishing (spear-phishing) using the leaked personal details.
- **Technical Safeguards:** Implementation of stricter network segmentation for databases containing Art. 9 GDPR data.
- **Credential Hygiene:** Use of Multi-Factor Authentication (MFA) across all academic and administrative portals.
- **Official Guidance:** Refer to the Federal Office for Information Security (BSI) at hxxps[://]www[.]bsi[.]bund[.]de for standard protection measures.