Osaka Metropolitan University cancels classes after suspected ransomware attack
A suspected ransomware attack knocked out around 500 servers at one of Japan's largest universities and may have exposed data on at least 130,000 people.
At a glance
- Osaka Metropolitan University says it believes ransomware disrupted its IT infrastructure, according to The Record.
- About 500 servers stopped working, hitting email, payroll, HR, library and academic systems; classes were cancelled through at least Thursday.
- Names, addresses and email addresses of at least 130,000 current and former students and staff may have been exposed.
- No group has claimed the attack, and the university has not confirmed data theft or a ransom demand.
Osaka Metropolitan University (OMU), one of Japan's largest universities, has cancelled classes after a suspected ransomware attack took down a large part of its IT infrastructure, The Record reported on October 6. The university said it believes ransomware caused the disruption, which began late last week, and that information on at least 130,000 people may have been exposed.
What happened
According to The Record, OMU said roughly 500 servers stopped operating as a result of the incident. The university is investigating the attack with outside cybersecurity specialists and has reported it to Japan's data protection authority and other government agencies.
Classes were cancelled through at least Thursday, with in-person teaching planned to resume on Friday. Online classes are being restored depending on how quickly systems are recovered, the report said.
Which systems were affected
The Record reported that the disruption reached the university's internal network and email, academic administration and educational support systems, financial accounting and payroll, human resources, library services and university websites.
Some services were spared. The university hospital and veterinary services continued to operate, and entrance exam and enrollment systems, which are hosted externally, were not affected, according to the report.
Who is affected
OMU said personal information of at least 130,000 people, including current and former students, faculty and staff, may have been exposed. The data in question includes names, addresses and email addresses. The Record noted that records linked to Osaka Prefecture University and Osaka City University, the two institutions that merged in 2022 to form OMU, may also be involved.
The university has not confirmed whether personal data was actually stolen. At the time of reporting, no ransomware group had claimed responsibility, and OMU had not disclosed details of any ransom note or demand.
What to do
Students, alumni and staff of OMU and its predecessor institutions should expect follow-up notices from the university and be cautious with unsolicited emails, calls or messages that reference the incident, since exposed names, addresses and email addresses are commonly reused in targeted phishing. Universities with similarly centralised infrastructure can use incidents like this to review network segmentation, offline backups of critical administrative systems and recovery plans that keep teaching running when core services go down.
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



