2026 LMU Munich — student registration standing data accessed; GDPR Art. 34 notice
Data compromised
Student registration standing data (as provided): names, DOB, gender, place/country of birth (some); term-time/home addresses; phones (some); LMU and other emails (some); bank details (IBAN, account holder); possible health insurance numbers, BAföG numbers, course-of-study and prior qualifications; individual Art. 9 leave-of-absence data. Exam results and individual academic performance expressly NOT affected. No indication of publication at notice time.
Technical writeup
Verified LMU Munich GDPR Article 34 notice — September 19, 2026. Unauthorized actor accessed standing student-registration data in an LMU IT system; university assumes data were retrieved; modification prevented; teaching uninterrupted after short registration pause. Investigation with Bavarian State Criminal Police Office ongoing. Affected server isolated; forensics and dark-web monitoring underway. No published headcount. recordsAffected 0; companyConfirmed true.
Root cause
Unauthorized actor gained access to standing data relating to student registrations in an LMU IT system