Security Guides
LMU Munich Student Data Breach (About 600,000 Records): IBANs May Have Leaked — What Students and Alumni Should Do
LMU Munich says an attacker took about 600,000 student records spanning some 50 years, including IBANs from 2005 onward. What students, alumni and former exchange students should do.
For: current and former students of LMU Munich (Ludwig-Maximilians-Universität München), including former exchange students and applicants, and anyone who keeps student or member data for years. This article is based on LMU's official notices and does not cover attack or scam techniques.
What students and alumni should do today
Work out whether you may be affected — alumni, exchange students and applicants count
LMU says the entire data set in its admission system is affected, covering about 50 years. That includes current students, graduates, people who left without a degree and people who only applied.
If you studied at LMU as an international or exchange student, including from Japan, you may be affected if you were registered in that system. As of October 3, 2026, LMU had not started individual notifications, so you do not need to wait for a letter before taking the steps below.
If you gave LMU a bank account in 2005 or later, check your statements
LMU says bank details (IBAN and account holder name) are in records from 2005 onward. If you gave LMU a German or EU account for fees or refunds, check that account for direct debits you do not recognize.
If the account belonged to a parent or someone else, tell them too. If you closed the account when you left Germany, no debit can be taken from it; if you are not sure whether you closed it, ask the bank.
Ask your bank to reverse any direct debit you do not recognize
A SEPA Direct Debit (the EU-wide bank debit scheme) can be refunded on request within 8 weeks of the debit date, without giving a reason. A debit you never authorized can be reversed for up to 13 months.
If you find one, start the process in your own bank's app or at a branch. If you receive a contract or payment demand you do not recognize, contact that company as well.
Do not open links in emails claiming to be from LMU, a health insurer or the BAföG office
The data that may have leaked includes your name, address and email address, plus enrolment details, health insurance number and BAföG (German state student aid) number. With those, a scammer can write a very convincing message.
LMU also advises not to open attachments or links without careful checking, even in emails that seem personally addressed, and not to reveal bank details or passwords. If you get a message about a "refund" or a "required re-registration", open LMU's official website yourself to check (see What is phishing?).
You are not asked to change your LMU password
LMU says passwords were not affected and university accounts are secure. If you use the same password on other services, though, this is a good moment to stop reusing it (choosing a password manager).
What happened (from LMU's notices)
LMU published its first notice on September 19, 2026, and an update and revised FAQ on September 28. Everything below is taken from LMU's official notices.
September 16, 2026
LMU identifies the incident. An unauthorized actor had accessed an IT system holding standing data on student enrolments.September 19
First notice. LMU says it must assume the data was taken and that the Bavarian State Criminal Police Office (LKA) and investigating authorities are involved.September 22
Enrolment reopens.September 28
Update. The scope is about 600,000 records spanning about 50 years. No signs of publication or misuse so far; LMU continues close monitoring of the dark web (sites used for illegal trading that ordinary search engines do not show).September 30
The course management system (LSF) starts reopening in stages.
- Scope
- The entire data set in the admission system: current and former students over about 50 years, about 600,000 records. Applicants and others whose data was processed in the system may be included
- Identifying data
- Name, date of birth, gender, in some cases place or country of birth
- Contact details
- Address, phone number, email address
- Bank details
- IBAN and account holder name (records from 2005 onward; none collected before 2005)
- Numbers
- Health insurance number, BAföG (state student aid) number, where applicable
- Study history
- Previous qualifications, course of study, reasons for leave of absence. Reasons for leave may include special categories of personal data under Article 9 of the EU General Data Protection Regulation (GDPR), such as health information
- Differences by year
- Records up to and including 1994 contain only standing data and semester history. Records from 2005 onward contain more
- Not affected
- Passwords, exam information, grades, course content and individual performance
- Cause
- Not disclosed. LMU shut down the affected system, secured the data and is investigating with external experts
- Authorities
- The Bavarian State Criminal Police Office (LKA) is investigating. The relevant supervisory and law enforcement authorities have been informed
- Contact
- cybersicherheit@lmu.de
How to read it: "no sign of publication" does not mean safe
LMU says it has seen no sign so far that the data has been published or misused. That means nothing has been found yet, not that the data will never be used.
Your IBAN, name and address stay the same for years unless you change them. Do not check your statements just once; keep checking for several months.
What a leaked IBAN can be used for
| Leaked data | Possible misuse | What to do |
|---|---|---|
| IBAN + name + address | Direct debits set up in your name (for example online shopping) | Check statements; have unrecognized debits reversed by your bank |
| Name + email + enrolment details | Convincing emails that claim to be from LMU | Do not open links; open the official website yourself |
| Health insurance or BAföG number | Messages claiming to be from an insurer or the student aid office | Do not treat a correct number as proof a message is genuine |
An IBAN alone does not let anyone log in to your online banking or move money out of your account. In the Odido case in the Netherlands, the Dutch Banking Association also said most people do not need to change their account (see the Odido data breach).
A SEPA direct debit, however, is started by the company collecting the money on the strength of a mandate (authorization) from the account holder, and the bank does not check that mandate each time. That is why spotting and reversing unrecognized debits is the most reliable thing an account holder can do.
This site's view: former exchange students who have gone home are the least likely to notice
Former international students who have returned home sometimes keep their German account open and rarely look at its statements. If the address on file is an old address in Germany, letters from the bank or a collecting company will not reach them either.
If you are unsure whether you closed an account, ask the bank, and consider closing it if you no longer use it. The 13-month limit for reversing unauthorized debits means leaving statements unread is the real risk.
For organizations that keep student or member data for years
The data involved covered about 50 years of student and alumni records. Universities do need to keep some records for a long time, such as proof of enrolment and degrees. Bank details and health insurance numbers, however, are collected for enrolment procedures. LMU has not said why it kept them.
With that in mind, there are three general things any organization holding student or member data can review.
Separate records you must keep long-term from data needed only for a procedure
Proof of a degree needs name, date of birth, enrolment period and degree. Bank details and insurance numbers are often not needed once the enrolment procedures are complete. For each field, check whether a law or regulation requires you to keep it, or whether there is simply no process to delete it.
Set a deletion date for bank details of graduates and former members
Article 5(1)(e) of the GDPR requires that personal data be kept in a form that identifies people for no longer than necessary for its purpose (storage limitation).
Bank details of graduates or former members are not used in daily work but are still exposed in a breach. Set a retention period and delete automatically when it ends. Manual deletion does not last.
Move old records out of the system used for everyday procedures
If a system that many people use every year, such as admissions, also holds decades of old records, a breach of that system exposes all of them. Move alumni records to separate storage with separate access rights, so that the everyday system cannot read them directly. See the security baseline for organizations.
Other education-sector cases: the Canvas (Instructure) breach for a learning management system, and the Mathspace breach for a learning platform.
Sources (public record)
The facts in this article are based on the public information below. We do not speculate on the undisclosed method or cause of the intrusion.
- LMU, "Information über einen Datenschutzvorfall" (September 19, 2026) — lmu.de
- LMU, "Update zum Datenschutzvorfall" (September 28, 2026) — lmu.de
- LMU, "Questions about the data security incident" (FAQ, updated September 28, 2026) — lmu.de (English) / lmu.de (German)
- European Commission, Your Europe, "Payments, transfers and cheques" (8-week refund for direct debits) — europa.eu
- Stiftung Warentest, "Lastschrift zurückholen" (8 weeks with a mandate, 13 months without) — test.de
- Directive (EU) 2015/2366 (PSD2), Articles 71 and 77 — EUR-Lex
- Regulation (EU) 2016/679 (GDPR), Articles 5 and 9 — EUR-Lex
Update history
2026-10-03: First version, based on LMU's first notice of September 19 and its update and FAQ of September 28. LMU's investigation is ongoing; we will update when it notifies affected people or discloses the cause.
Read next
- Protecting yourself from follow-on scams: What is phishing? / Fake virus warnings (tech support scams)
- Another case with leaked IBANs: Odido (Netherlands, IBANs and ID numbers)
- Education-sector cases: Canvas (Instructure) / Mathspace (Australia and New Zealand)
- Other 2026 cases: Data breaches and cyberattacks in 2026
- For operators: The security baseline for organizations
FAQ
QWhat was leaked in the LMU Munich breach?
According to LMU's September 28, 2026 update and FAQ, about 600,000 records from its admission and enrolment system are affected. They can include name, date of birth, gender (in some cases place or country of birth), address, phone number, email address, bank details (IBAN and account holder name), health insurance number, BAföG (German state student aid) number, previous qualifications and course of study, and reasons for leave of absence. Passwords, exam information, grades and course content were not affected.
QAm I affected?
LMU says the entire data set in the admission system is affected, covering current and former students over roughly 50 years. Applicants and other people whose data was processed in that system may also be included. Former international and exchange students, including those from Japan, may be affected if they were registered in that system.
QWhich years include bank details?
LMU says records up to and including 1994 contain only standing data and semester history, and bank details appear only in records from 2005 onward; it did not collect bank details before 2005. If you gave LMU an account in 2005 or later, assume your bank details are included.
QWill I be notified individually?
As of October 3, 2026, LMU had not announced individual notifications. It says it will inform affected people once it knows more, and will notify them without delay if monitoring or the investigation shows the data has been published or misused. Its contact address is cybersicherheit@lmu.de.
QWhat can someone do with my IBAN?
An IBAN (International Bank Account Number) alone does not let anyone log in to your online banking or send money from your account. The risks are that someone uses your name and IBAN to set up a direct debit (SEPA Direct Debit), for example for online shopping, and that scammers quote your IBAN to make messages look genuine. Check your statements and ask your bank to reverse any debit you do not recognize.
QCan I reverse a direct debit I did not authorize?
Under the EU Payment Services Directive (PSD2), and as German consumer testing organization Stiftung Warentest explains, you can ask your bank to refund a SEPA direct debit within 8 weeks of the debit date without giving a reason. If you never gave a mandate (authorization) for the debit, you can have it reversed for up to 13 months. Do this through your own bank's app or branch.
QWhat caused the breach?
As of October 3, 2026, LMU had not disclosed how the attacker got in or for how long. It identified the incident on September 16, shut down the affected system, secured the data and is investigating with external experts. The Bavarian State Criminal Police Office (LKA) is involved, and LMU says the relevant supervisory and law enforcement authorities have been informed.