Ludwig-Maximilians-Universität München published a GDPR Article 34 notice on September 19, 2026: an unauthorized actor gained access to standing data for student registrations stored in an LMU IT system. The university says it must currently assume those data were retrieved. Modification was prevented, teaching continued, and registration paused only briefly with extended deadlines.
This is a verified LMU Munich data breach via the university’s own notice. Canonical record: https://breachhistory.com/lmu-munich/lmu-munich-student2026. Primary: LMU press notice.
What happened
Attackers reached a registration-related system holding standing data collected when students enroll. LMU isolated the affected server, brought in IT forensics, and is working with the Bavarian State Criminal Police Office. Dark-web monitoring is underway. No headcount was published at notice time.
Timeline
- September 19, 2026: Public Art. 34 notice describing unauthorized access and assumed retrieval.
- Ongoing: Forensic investigation with police; registration resumes after short interruption with extended deadlines.
What was exposed — and what was not
As provided at registration: names, DOB, gender, sometimes place/country of birth; addresses; phones (some); LMU and other emails; bank details such as IBAN; possible health-insurance and BAföG numbers; course-of-study and prior qualifications; individual Art. 9 leave reasons in some cases.
Expressly not affected: examination information and specific individual academic-performance data. No indication of publication yet, per LMU.
Who is at risk
Current and recent students, registrants who supplied banking fields, and staff who process enrollment.
What you should do
- Treat “LMU IBAN verify” emails as phishing.
- Monitor bank accounts tied to tuition or BAföG.
- Change reused passwords on LMU email.
- Use only typed lmu.de URLs.
- Contact [email protected] from the official notice — not reply-all to cold mail.
- Watch SCHUFA activity if sensitive identifiers were shared.
- Do not send passport scans to anyone “securing your LMU file.”
- Keep the Art. 34 URL for banks if fraud appears.
- International students: confirm embassy contact details were not in scope before panicking.
- Parents paying tuition: verify wire instructions out-of-band.
Industry context
Readers comparing this incident to other September 2026 disclosures should separate company-attested facts from actor marketing. Leak-site volume claims, raw row counts, and “complete archive” language are negotiation tools. Regulators and Have I Been Pwned-style analyses often cut those numbers dramatically once duplicates are removed.
Phishing follows every headline. Attackers will reuse the real organization name, a plausible deadline, and a payment or “secure portal” theme. Help desks should verify using phone numbers from letterhead, not from the inbound message.
If forensics later revise scope, publish an amendment with dates. Catalogs should track those amendments so researchers are not citing stale counts.
Canonical record and sources
Evidence-folder note 1 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 2 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 3 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 4 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 5 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 6 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 7 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 8 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 9 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 10 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 11 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 12 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 13 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 14 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 15 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 16 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 17 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 18 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 19 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 20 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 21 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 22 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 23 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 24 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 25 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 26 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 27 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 28 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 29 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 30 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 31 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 32 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 33 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 34 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 35 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 36 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 37 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 38 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 39 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 40 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 41 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 42 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 43 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 44 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 45 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 46 for lmu-munich-student-registration-breach-september-2026: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.