Osaka Metropolitan University hit by suspected ransomware
Osaka Metropolitan University (OMU), one of Japan's largest universities, has cancelled classes and taken much of its IT infrastructure offline after a suspected ransomware attack that started late last week.
The university said on Tuesday that its internal network, email and several administrative and academic systems are unavailable. OMU believes ransomware caused the disruption and is working with outside cybersecurity specialists to investigate. It has not named the attackers and has not said whether it received a ransom demand.
Hundreds of servers down
The outage covers a wide range of university operations. Systems for academic administration, educational support, financial accounting, payroll, human resources and library services are affected. The university's websites and internal network are also down.
Japanese media reported that about 500 servers stopped working after the attack. The figure came from university officials at a press conference on Monday.
Some services are still running. Entrance exam applications and enrollment procedures are hosted on external servers and remain available, according to the university. The electronic medical record system at the university hospital was not affected, and the hospital kept providing medical services. OMU's veterinary clinical center also stayed open.
Data of 130,000 people may be exposed
According to Japanese media, information on at least 130,000 people linked to the university may have been exposed. This includes current and former students, faculty members and others associated with OMU.
The data that may be affected includes names, addresses and email addresses. It also includes data connected to Osaka Prefecture University and Osaka City University, the two institutions that merged in 2022 to form OMU.
The university has not confirmed that any personal data was stolen. On Tuesday it said it was still investigating whether information had leaked. OMU has reported the incident to Japan's data protection authority and to other government agencies.
Classes on hold until Friday
Because of the disruption, classes are cancelled through at least Thursday. OMU plans to bring back in-person teaching on Friday. Online classes will restart depending on how quickly systems are restored.
A busy period for Japanese incident disclosures
The attack is the latest in a series of recently disclosed cyber incidents in Japan. There is no evidence that any of them are connected.
Over the weekend, media group Nikkei said a compromised employee account was used to send roughly 9,000 malicious emails to internal and external contacts, including journalistic sources. We covered that incident in our report on the Nikkei account hijacking.
Other Japanese companies that have recently disclosed cyber incidents include brokerage Daiwa Securities, delivery firms Yamato Transport and Sagawa Express, insurer Dai-ichi Life and broadcast equipment maker Ikegami Tsushinki.
Our Take
The OMU incident shows how much a single attack can take down at a large university. Payroll, HR, finance, teaching tools, the library and email all failed together. This suggests that many core systems shared the same internal network, which gave the attackers a wide reach once they got in.
The parts that kept working are worth noting. Enrollment and exam systems ran on external servers, and the hospital's medical record system stayed online. Separating critical services from the main campus network appears to have limited the damage. Other institutions could learn from that when they plan their architecture.
Universities remain attractive targets. They hold large amounts of personal data on students, staff and alumni, and they run complex, often decentralised IT. The recent ransomware attack at UIC, which hit College of Medicine systems, is another example from the same week. OMU's merger in 2022 adds another factor: its systems hold data inherited from two predecessor universities, which may increase the number of people affected.
There are several things to watch. If a ransomware group claims the attack, or if data appears on a leak site, that would answer the open question about data theft. It is also worth watching how long full recovery takes, especially for online classes. Finally, the investigation should show whether the 130,000 figure grows as OMU works through what the attackers could access.
