Das Mannheimer Barockschloss und der Ehrenhof unter blauem Himmel.

Cyberattack on a Chair’s Server

Unknown individuals have gained unauthorised access to a server belonging to the Chair of Economic and Business Education – Learning, Design and Technology at the University of Mannheim. The chair holder subsequently received a letter in which the attackers threatened to publish the data stored on the server.

This text was translated from German by AI / DeepL Pro.

After the verification of the attack took place on 17 September, the server was immediately disconnected from the university network and the relevant parties at the University of Mannheim (University IT, Chief Information Officer, information security unit and data protection service) were notified. All relevant external bodies (State Criminal Police Office, Baden-Württemberg Cybersecurity Agency, data protection officer and State Commissioner for Data Protection and Freedom of Information) have also been involved.

The forensic investigation and further clarification of the facts are still ongoing. It is therefore currently not possible to provide reliable information on when the unauthorised access began, which data has been affected, or the extent to which data has fallen into the hands of third parties. In particular, the State Criminal Police Office and the Baden-Württemberg Cybersecurity Agency are supporting the university in its investigation and in implementing security measures to prevent any further attacks.

Potentially affected data and risks

According to initial findings, the following groups of people and data may be affected:

  • Students who have completed coursework and examinations at the Chair of Economic and Business Education – Learning, Design & Technology: It is currently unclear which data was copied by the attackers or whether this data is being misused. Academic and examination operations remain unaffected. The University of Mannheim still holds the complete sets of the affected data. Any manipulation of examination results can be ruled out.
  • Staff members of the Chair of Economic and Business Education – Learning, Design & Technology: Personnel data required for the establishment of employment contracts – such as application documents and applications for recruitment or contract extensions – as well as data required for the settlement of expenses related to business trips may be affected.
  • Researchers and institutions that cooperate or have cooperated with the chair: Data processed in connection with the chair holder’s official duties, or in relation to procurement or publications, may be affected.

In all cases, it is still unclear whether, and if so, which data has actually been stolen and whether other groups of people are affected. As soon as further details become available, the individuals and institutions concerned will be informed directly, where possible.

Although the University currently has no evidence of any misuse of the data, it advises everyone to be particularly vigilant and to take general precautions. In particular, please verify any messages that (purport to) come from the chair of Economic and Business Education – Learning, Design & Technology.

Further information can be found in the FAQs.

Back