In late August 2026, a security incident affected a local Zimbra email system operated by the LECAD Laboratory for Engineering Design at the University of Ljubljana, Faculty of Mechanical Engineering. An attacker exploited a vulnerability in the software and partially encrypted archived email correspondence stored in a single user mailbox.
The affected system operated separately from the Faculty’s central email infrastructure. The Faculty’s official email service and other central information systems were therefore not affected.
The system was taken offline, security updates were applied, and the data were restored from backups. No permanent data loss has been identified, and there is currently no evidence confirming that data were exfiltrated.
Because the available technical logs do not allow us to fully reconstruct the attacker’s actions, we cannot completely rule out the possibility that archived correspondence was accessed or copied. We are publishing this notice in the interest of transparency, as the archive also contained correspondence with external contacts who cannot all be notified individually.
No specific action is currently required. As a general precaution, we recommend remaining alert to unexpected emails and verifying any unusual requests sent in the name of the Faculty or the LECAD Laboratory for Engineering Design.
The incident has been reported to the Information Commissioner of the Republic of Slovenia and to SI-CERT.
For further information, please contact helpdesk@fs.uni-lj.si.
