Heise.De Munich Incident: 120,000 Student Records Allegedly Compromised
Article Content
- •Over 120,000 student records may be compromised, but no confirmation of a data leak.
- •LHM-Services is investigating potential unauthorized access by a former employee.
- •The incident is tied to alleged security flaws in SharePoint server configurations.
A report suggests that sensitive personal data of over 120,000 students in Munich is circulating on the dark web. The IT company LHM-Services, which manages the data, claims it learned of the incident through the media. The Abendzeitung newspaper reported that names, addresses, birth dates, nationalities, and schools were potentially exposed. However, LHM-Services has not confirmed any data leak and states that no datasets have been found on the dark web. The company is investigating the suspicious download behavior of a former employee and has filed a criminal complaint. They also informed Bavaria's State Data Protection Officer. The incident is linked to allegedly insecure SharePoint servers, but LHM-S denies any unauthorized access occurred. The situation remains unclear as the investigation continues.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Landeshauptstadt München in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…