Skip to content

Security1 publisher2 min readPublished

LMU Munich assumes an intruder retrieved enrollment records holding bank and insurance data

LMU Munich detected the intrusion on Wednesday and disclosed it on Saturday, and it still cannot say when the access began or how many of its more than 52,000 students are in the enrollment file.

The Watch · Security desk

Illustration accompanying LMU Munich assumes an intruder retrieved enrollment records holding bank and insurance data

What happened

  • LMU Munich said on Saturday that an attacker accessed enrollment data on one of its IT systems and that it must now assume the data were in fact retrieved.
  • The university detected the incident on Wednesday and has not yet determined when the unauthorized access began or how long it lasted.
  • Examination records, course content and individual academic performance were not affected, and LMU has found no sign the data were altered, deleted or published.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Students carry the fraud risk: a bank account number next to a name, a date of birth, a university email address and an insurance number is enough to attempt direct debits and to write mail that passes for the registrar.
  • constraint With no start date for the access, there is no defined period for anyone to monitor, so advice to watch bank accounts has no end point and no baseline.
  • decision A registry holding health insurance numbers and financial aid identifiers is regulated data infrastructure, and universities now have to decide whether enrollment databases keep being scoped as ordinary administrative systems.
  • cost Containment cost students time in the academic calendar: enrollment stopped mid-cycle and LMU has to extend deadlines so nobody loses a semester to the shutdown.

LMU's own list puts bank account information alongside names, dates of birth, contact details and LMU email addresses, together with the course of study and previous qualifications [5]. Health insurance numbers and identifiers tied to Germany's student financial aid program may be in the same set [6]. In some cases, so are the reasons a student gave for requesting a leave of absence [7]. Those fields support direct debit fraud against a named account holder, and they support phishing that looks like it came from the registrar, because whoever holds them knows the course, the university address and the aid status.

The university detected the incident on Wednesday and published its statement on Saturday, three days later [18]. It still cannot say when the unauthorized access started or how long it ran [9], or how many people are in the file and how much data was taken [10]. Without a start date there is no window to monitor.

"Currently, we must assume that this data were in fact retrieved," the university said [2]. That is a firmer statement than most first-week disclosures carry, and LMU made it while also saying it has found no evidence the data were altered or deleted, and no indication so far that the information has been published or misused [4].

Examination records, course content and individual academic performance were not affected [8]. So the examination data were on a system the intruder did not reach, and the banking and health identifiers were on one that was reached [1].

Containment took the affected server off the network and brought in outside cybersecurity specialists, with law enforcement involved in the investigation [12]. Several systems that were not directly affected were shut down as a precaution, and some internal services went unavailable [13]. Enrollment stopped briefly, is expected to resume this week, and affected deadlines are being extended; teaching continued [14]. "I can't register for courses, I can't view my grades," one student told the German regional outlet Rosenheim24 [16].

The attacker has not been identified, and LMU has not said whether it received a ransom demand [11]. The university has asked specialists to watch dark-web forums and other platforms for signs the records are circulating [15]. On the wider pattern, The Record lists recent ransomware at the University of Texas, the University of Oklahoma, Stanford and the University of Michigan, several of those after holiday breaks, with email disruption at the University of Pennsylvania in October and attacks on Columbia and Harvard last year [17].

What to watch

  • A start date for the unauthorized access. That would finally bound the period students need to monitor accounts.
  • A count of affected individuals; LMU has not said how many people are in the enrollment file.
  • Any appearance of LMU enrollment records on a leak forum. The university has specialists watching for it.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories