Back Therecord.Media Osaka Metropolitan University cancels classes after suspected ransomware attack
One of Japan’s largest universities canceled classes and shut down a large part of its IT infrastructure following a suspected ransomware attack that began late last week.
Osaka Metropolitan University said on Tuesday that the outage left its internal network, email and a range of administrative and academic systems unavailable.
OMU said it believes ransomware caused the disruption and is investigating the attack with outside cybersecurity specialists. It has not identified the attackers or said whether it received a ransom demand.
The outage affected systems used for academic administration, educational support, financial accounting, payroll, human resources and library services, as well as the university's websites and internal network.
500 servers stopped operating following the attack, Japanese media reported , citing university officials at a press conference Monday.
The reports said information belonging to at least 130,000 current and former students, faculty members and others associated with the university may have been exposed. The potentially affected information includes names, addresses and email addresses, as well as data linked to Osaka Prefecture University and Osaka City University, which merged in 2022 to form OMU.
The university has not confirmed that personal data was stolen and said Tuesday that it was still investigating whether any information had been leaked. It has reported the incident to Japan's data protection authority and other government agencies.
The disruption forced OMU to cancel classes through at least Thursday. The university said it plans to resume in-person classes Friday, while online classes will restart depending on the progress of system recovery.
Systems used for entrance exam applications and enrollment procedures remain available because they are hosted on external servers, according to the university.
The attack also did not affect the electronic medical record system at the university hospital, which continued providing medical services. Its veterinary clinical center also remained operational.
The incident comes amid several recently disclosed cyber breaches in Japan, although there is no evidence that they are connected.
Over the weekend, Japanese media giant Nikkei disclosed that a compromised employee account had been used to send roughly 9,000 malicious emails to internal and external contacts, including journalistic sources.
Other Japanese companies that have recently disclosed cyber incidents include brokerage Daiwa Securities, delivery companies Yamato Transport and Sagawa Express, insurer Dai-ichi Life and broadcast equipment manufacturer Ikegami Tsushinki.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
