Ludwig Maximilian University of Munich (LMU) disclosed an IT security incident in which attackers apparently copied extensive student enrollment records. Potentially exposed information includes identity and contact details, along with sensitive financial data, BAföG student-aid information, and health-insurance records.
LMU isolated affected systems, expanded security monitoring, and began forensic investigations while monitoring relevant dark-web sites for leaked data. The Bavarian State Criminal Police Office is investigating; LMU said it had no indications at the time of disclosure that the data had been published or otherwise misused.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
LMU Munich discovered an intrusion into its IT systems on Wednesday of the week reported. The university said apparently complete student-enrollment records were copied, potentially including identity, contact, bank, BAföG, and health-insurance data.
The Bavarian State Criminal Police Office initiated an investigation into the intrusion. At the time of reporting, LMU said it had no indication that the copied records had been published or otherwise misused.
LMU took the affected systems offline and isolated them, expanded security monitoring, and began forensic examinations. It also arranged monitoring of relevant darknet portals and advised students to be alert to study-related contact attempts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.