Hacker breaches LMU Munich database holding bank and personal data of students
An unknown hacker accessed matriculation files containing bank details, addresses, and educational records at Ludwig Maximilian University of Munich, prompting an investigation by the Bavarian State Criminal Police Office.
Breach of student matriculation records
An unidentified hacker gained unauthorized access to an IT system housing matriculation master records at Ludwig Maximilian University of Munich (LMU), compromising sensitive personal and financial data. The institution confirmed that the compromised database contains student names, postal addresses, email addresses, places of birth, bank account details, and records of previous educational qualifications. The compromised IT system contained central registration master data used for official university enrollments, leaving personal records vulnerable to exfiltration. LMU has not disclosed the precise number of individuals affected or confirmed whether the breach is limited to currently enrolled students or extends to former alumni. During the 2025/26 winter semester, more than 52,000 students were registered at the university, making it one of the largest higher education institutions in Germany. University administrators assured the student body that the security breach would cause no academic disadvantages, but advised everyone to exercise heightened vigilance regarding unsolicited messages, fraudulent bank activity, and suspicious contact attempts.
Police investigation and darknet surveillance
The Bavarian State Criminal Police Office (Bayerisches Landeskriminalamt) has initiated an investigation into the cyberattack. Specialized IT forensics teams and external cybersecurity contractors were deployed to inspect the university network, secure vulnerabilities, and defend the systems against potential follow-up attacks. External specialists are continuing forensic audits of the compromised servers to determine the exact technical entry point used by the attacker. Cyber investigators are actively monitoring darknet platforms and illicit marketplaces to detect whether any stolen student datasets are published or offered for sale. As of Sunday, 20 September 2026, authorities confirmed that none of the compromised records had surfaced on the darknet. Criminal actors regularly exploit stolen identity and banking records to commit identity theft, execute fraudulent transactions, or make unauthorized online purchases. The breach at LMU follows a separate cyber incident involving the Berlin city administration, where extortionists leaked at least 1.2 million records online after city authorities refused to yield to ransom demands.
- LMU technical staff detect unauthorized intrusion into student matriculation system
- University publishes online notice informing students of the data breach
- Bavarian State Criminal Police Office and IT forensics teams confirm active investigation
Scrutiny over notification timeline
University technical staff initially detected the intrusion on Wednesday, 16 September 2026, but the administration waited until Saturday, 19 September 2026, to publish an advisory on its website. This three-day delay prompted criticism from state lawmakers regarding compliance with statutory data privacy standards. Florian von Brunn, a member of the Bavarian State Parliament and digital policy expert for the SPD parliamentary group, stated that the delayed disclosure required immediate clarification from university leadership.
The General Data Protection Regulation requires affected persons to be notified without delay, and not days later and sometime on the first Saturday of Oktoberfest.
Von Brunn described the cyberattack on the university as shocking given the substantial IT expertise present across the institution. He also criticized the ongoing lack of transparency regarding when the unauthorized access began and how long the intruder operated inside the network before being discovered.
Causes, course of events and responsibilities must now be put on the table.


