Cyber & AI intelligence
Wasteland.
Briefs indexed3020
Issues31
Published Mondays07:30 CT
▣ Breach OSAKA-METROPOLITAN 2026-10-06

Osaka Metropolitan University: Ransomware Hits Virtualization Platform, 500 Servers Down

"At a press conference on Monday, October 5, Osaka Metropolitan University (OMU) said it believes a ransomware attack caused the large-scale system failure that began early on Friday, October 2. About 500 servers stopped…"

At a press conference on Monday, October 5, Osaka Metropolitan University (OMU) said it believes a ransomware attack caused the large-scale system failure that began early on Friday, October 2. About 500 servers stopped running, most of the university's backups were encrypted, and personal data on at least 130,000 people sat on the affected systems. Whether any of that data was actually taken is still under investigation. All five campuses are affected and classes are cancelled through October 8. The university has given no recovery timeline. All eight sources for this brief are secondary reporting, mostly from Japanese outlets covering the press conference. None is a primary statement from the university, so the details below are attributed to the outlets that reported them.

What Happened

CHOTTO NEWS, citing Asahi Shimbun and other outlets, reports that the university's maintenance contractor first noticed the problem at about 00:20 on October 2, and found signs of data tampering by about 04:00. The university's own outage page, as quoted by 100点BBS, gives the start time as about 00:30. OMU set up a crisis response headquarters shortly after 08:00 that morning.

The early public statements on October 2 called the cause "under investigation." Korean outlets SBS and Seoul Economic Daily, citing NHK, reported the same day that the university did not know the cause or when it could recover. The ransomware explanation came only at the October 5 press conference. President Hiroyuki Sakuragi apologised and said, according to Jiji Press, "It is regrettable that we could not prevent the incident."

The outage covers the campus network, internal email, the student and faculty portals, academic administration, and, according to CHOTTO NEWS, finance, HR and payroll, and library systems. It reaches all five campuses: Morinomiya, Sugimoto, Nakamozu, Abeno and Rinku. A student quoted by Yomiuri, via AloJapan, said the timetable app and the digital student ID both stopped working. The university's main website (www.omu.ac.jp) was still down on the night of October 2. Since then OMU has posted updates through an emergency site kept separate from the affected infrastructure (www.omu.moe), an "OMU Entrance" status page, and its official X account.

Outlets agree on these operational impacts:

OMU has reported the incident to Osaka Prefectural Police and the Ministry of Education (MEXT). CHOTTO NEWS reports it also notified the Personal Information Protection Commission on October 5. The university says it cannot comment on whether a ransom was demanded because the investigation is ongoing. No ransomware group has been named, and none of the sources mention a leak-site listing.

What Was Taken

No data theft has been confirmed. The 130,000 figure is the minimum number of people whose records were on the affected systems, not a confirmed count of stolen records. The sources describe that group differently:

The sources also list different data types. It is unclear whether each outlet reported part of the same list or whether accounts actually differ:

The dataset reaches back past the April 2022 merger that created OMU. Security Measures Lab reports it includes students of the former Osaka City University from 1995 onward and of the former Osaka Prefecture University from 2005 onward. That means many of the people affected left the university years ago and may not expect to hear from it. If the data was exfiltrated, ID photos combined with contact details would be well suited to targeted phishing and impersonation.

Why It Matters

This is a near-total loss of a university's IT infrastructure, not an attack on a few endpoints. The attackers hit the shared virtualization layer and encrypted most backups, which removed both the production systems and the main way to recover them. That is why OMU could not give a recovery date three days in.

The incident also fits a pattern in Japan. Korean outlets SBS and Seoul Economic Daily place it alongside Times Car's disclosure of 6.6 million leaked user records on September 29, the July intrusion into the Government Solution Service that exposed about 246,000 public officials, and a leak of about 7.1 million records from an LY Corp. game service. CHOTTO NEWS compares it with the 2022 ransomware attack on the Tokai National Higher Education and Research System (Nagoya and Gifu universities), where up to about 40,000 people's data was at risk. By server count and backup loss, OMU is much worse.

Some things did go right. The admissions portals ran on external hosting and kept working. The clinical systems were apparently segmented from the affected infrastructure. Both choices limited the damage.

The Attack Technique

What is known about how the attackers got in is limited. MBS (via Security Measures Lab) and CHOTTO NEWS report that they broke into the virtualization platform underlying the university's information systems. That let them shut down or encrypt about 500 virtual servers at once and reach most of the backups. The initial access vector, the hypervisor platform, the ransomware family, the dwell time and any exfiltration method have not been disclosed. There are no published indicators of compromise.

The pattern matches ransomware campaigns that target hypervisors (ESXi and similar). The attacker gets administrative access to the management plane, then encrypts virtual machine storage and any backup repositories reachable from the same trust domain. This is an inference from the reported impact, not something the university has stated.

What Organizations Should Do

  1. Treat the hypervisor management plane as tier zero. Isolate vCenter and other hypervisor management interfaces on a dedicated network. Require phishing-resistant MFA, remove links to general directory accounts where possible, and alert on mass VM power-off or datastore changes.
  2. Make at least one backup copy unreachable from production. Use immutable or offline copies held under separate credentials and a separate administrative domain. If a domain or hypervisor admin can delete or encrypt every backup, there is no real backup.
  3. Test restoring the whole environment, not single files. Practise rebuilding core services such as identity, email, the portal and student records from clean media. Measure how long it takes before an attacker forces the test.
  4. Minimise and segment historical records. Data on students going back to 1995 should not sit on live systems. Apply retention schedules and archive former-student records offline.
  5. Host critical public services off-platform. Admissions sites stayed up because they were external. Do the same for status pages, emergency communications and other time-critical services, and keep out-of-band contact channels ready in advance.
  6. Prepare for long-tail notification. If exfiltration is confirmed, many affected people will be alumni with stale contact details. Plan how to reach them, and warn them about phishing that uses their name, photo or student history.

Sources: Data Leak Suspected at University in Osaka due to Cyberattack Nipp... | 大阪公立大、ランサム攻撃でサーバー約500台停止——13万人の個人情報、流出有無は調査中 – CHOTTO NEWS | Another Cyber Security Incident in Japan - SBS뉴스 | 大阪公立大学で大規模システム障害、10月8日まで全授業休講 Web出願・入学手続のサイトは登録できる|受験ニュース - 100点BBS | 大阪公立大学、ランサムウェア攻撃で約500台のサーバー停止―バックアップの多くも暗号化、8日まで全授業休講セキュリティニュースのセキュ... | Osaka Public University Ransomware Attack: Nearly 500 Servers Down... | Osaka University Network Outage Fuels Fears Amid String of Cyberatt... | Cyberattack on Osaka University Shuts Down 500 Servers - Alo Japan...