Cyberattack on a Chair's Server

As soon as the attack was detected on 17 September, the server was disconnected from the university network, and all relevant departments at the University of Mannheim (University IT, Chief Information Officer, Department of Information Security, and the Data Protection Team) were notified. Moreover, the appropriate authorities outside of the university (State Office of Criminal Investigations (LKA), Baden-Württemberg Cybersecurity Agency (CSBW), data protection officer, and State Commissioner for Data Protection and Freedom of Information (LfDI)) were involved.
The forensic investigation and further clarification are still ongoing. We are therefore currently unable to provide reliable information about when the actors gained unauthorized access, what data was affected, or whether and to what extent data was obtained by third parties. The State Office of Criminal Investigations and the Baden-Württemberg Cybersecurity Agency are assisting the university with the investigation and with security measures to prevent future attacks.
Potentially affected data and risks
Initial findings point to the following groups of people and data that may be affected:
- Students who have completed coursework or examinations at the Chair of Economic and Business Education – Learning, Design & Technology: At this point, it is not yet clear which data was copied by the attackers and whether that data is being misused. Ongoing studies and examinations are not affected. The University of Mannheim still holds the complete sets of data affected. Any manipulation of examination results can be ruled out.
- Employees of the Chair of Economic and Business Education – Learning, Design & Technology: Personnel data required in the hiring process, such as application documents and request forms for hiring or contract renewal, as well as data required for the reimbursement of expenses related to business trips may be affected.
- Researchers and institutions that collaborate or have collaborated with the chair: Data processed in connection with the chair holder's official duties, procurement activities, or publications may be affected.
In all cases, it is still unclear whether any data was compromised and, if so, what data, or whether any other individuals or groups are affected. As soon as more detailed information becomes available, affected individuals and institutions will be informed directly wherever possible.
Although the university currently has no evidence that the data has been misused, we advise everyone to remain particularly vigilant. In particular, please exercise caution and verify the authenticity of any messages claiming to come from the Chair of Economic and Business Education – Learning, Design & Technology.
Further information, please go to our FAQs.