Decoding the world of cybersecurity

LMU breach expands to 600,000 records

LMU Munich says forensic work has established that its entire admissions-system dataset was affected by September’s cyberattack, covering around 600,000 records dating back roughly 50 years.

LMU breach expands to 600,000 records
Summary
  • LMU now says the entire dataset in its admissions system was affected by the September attack.
  • Around 600,000 records are involved, with older and newer records containing different categories of information.
  • The university says it has no current evidence that the data has been published or otherwise misused.

Ludwig Maximilian University of Munich has substantially increased the known scale of its September cyber incident, saying forensic work has established that the entire dataset held in its admissions system was affected.

The university, commonly known as LMU, said on 28 September that the system contains around 600,000 records covering current and former students and stretching back approximately 50 years. The finding materially extends what was known when the incident was first disclosed.

The categories of data vary according to the age of the record. LMU said records up to and including 1994 contain basic personal information and semester history, while more extensive information is present in later records. From 2005 onwards, that can include banking information where it was supplied.

Identity and contact information can also be present, alongside details relating to a person’s course of study and, in some cases, reasons for periods of leave. LMU said passwords, examination information, detailed academic performance records, and large volumes of sensitive data remain outside the affected dataset.

The university has not said that all 600,000 records contain every category of information. The age and content of individual records differ substantially, making the headline dataset count distinct from the number of people exposed to each type of data.

LMU said it continues to monitor for publication or misuse of information associated with the attack and currently has no indication that the affected data has appeared publicly or been abused. That distinction is important: compromise of a dataset establishes exposure, but does not by itself demonstrate subsequent criminal use.

The incident has also become an operational recovery exercise. The university took affected systems offline after detecting the attack and disconnected other systems as a precaution while security checks were carried out. Some services are now returning in stages, including systems supporting the start of the academic term.

LMU said access to its central online course system will initially be restricted to university and Munich academic networks, with VPN access required from outside. Other platforms have returned separately, while security checks continue on systems that remain unavailable.

The age of the affected records adds a less visible governance dimension. Universities can have legitimate reasons to preserve academic and administrative information for decades, including evidence required later for pensions or official records. LMU said its retention approach reflects a roughly 50-year period commonly used in higher education and clarified earlier privacy information that had referred to possible retention of up to 100 years.

Long retention periods increase the accumulated value of a compromised system. An application designed to support admissions or student administration can become a historical repository spanning multiple generations of students, leaving the consequences of a single incident much broader than the system’s current user base suggests.

The university is continuing its investigation with internal, external, and public-sector security support. The remaining questions include how the attacker obtained access, whether information was removed from the environment, and whether the monitoring now under way identifies any later publication or misuse.

×