Das Mannheimer Barockschloss und der Ehrenhof unter blauem Himmel.

Cyberattack on a Chair’s Server: Answers to Frequently Asked Questions

This text was translated from German by AI / DeepL Pro.

  • What happened?

    The Chair of Economic and Business Education – Learning, Design & Technology was the target of a cyberattack. During the attack, unknown individuals gained access to the chair’s server. On 17 September, the chair holder received an email in which the attackers threatened to publish data. 

  • What action was taken once verification of the incident took place?

    The server was shut down after verification of the incident took place and isolated from the rest of the (university) cloud system.

    The university’s crisis management team convened shortly after the attack came to light and has been meeting regularly ever since. The relevant bodies at the University of Mannheim (University IT, Chief Information Officer, information security team and data protection service centre) are handling the incident. All relevant external bodies (State Criminal Police Office, Baden-Württemberg Cyber Security Agency, data protection officer and State Commissioner for Data Protection and Freedom of Information) are also involved.

  • What data is affected?

    The final technical and forensic investigation into the attack, carried out in close cooperation with the relevant investigating authorities and external bodies, is still ongoing. It is therefore currently not possible to provide reliable information on when the unauthorised access began, which data is affected, or the extent to which data has fallen into the hands of third parties.

  • Which and how many individuals and data records are affected?

    According to initial findings, the following groups of people and data may be affected:

    • Students who have completed coursework and examinations at the Chair of Economic and Business Education – Learning, Design & Technology
      This may include coursework and examinations such as term papers, seminar papers and final theses, as well as the corresponding grade lists. It is currently unclear which data was copied by the attackers or whether this data is being misused.
      Examinations have not been disrupted. The University of Mannheim still holds the complete sets of the affected data. The examination processes have been completed and the results have been recorded in the Campus Management System Portal². Any manipulation of the examination results can be ruled out.
    • Staff members of the Chair of Economic and Business Education – Learning, Design & Technology
      Personnel data of Chair’s employees that is required for the establishment of employment contracts – such as application documents and applications for recruitment or contract extensions – as well as data required for the settlement of expenses related to business trips, may be affected.
    • Researchers and institutions that cooperate or have cooperated with the chair
      Data from institutions and researchers cooperating with the chair may be affected, as well as data processed in connection with the chair holder’s official duties, procurement activities or publications.

    In all cases, it remains unclear whether, and if so, which data has actually been stolen and whether further groups of people are affected. As soon as more detailed information becomes available, the individuals and institutions affected will be informed directly, where possible. The exact number of people affected is not yet known.

  • Has the data been published, or are there any indications of misuse?

    According to current information, there is no evidence to suggest that the attackers have published the data sets they obtained.

  • Has the police been involved?

    As soon as the incident came to light, the Baden-Württemberg State Criminal Police Office was immediately notified. 

  • What security measures can I take?

    1. Be vigilant: Check incoming emails for irregularities (tampering with the sender’s address, spelling mistakes, etc.) before opening them. In particular, check messages that (purportedly) originate from the chair of Economic and Business Education – Learning, Design & Technology.
    2. Only disclose information after thorough examination: For example, staff members at the University of Mannheim will never ask you for your login details. If sensitive data is requested in the name of the Chair of Economic and Business Education – Learning, Design & Technology, please verify for your own safety – for example by telephone – whether the request actually originates from the relevant chair or the University of Mannheim.
    3. Check your bank account transactions: If you notice any unauthorised or unexpected transactions, please contact the University of Mannheim and your bank immediately.
    4. Further recommendations and security measures can be found at https://www.bsi.bund.de.
  • Who can I contact if I have further questions?

As of: 22 September 2026