Security1 publisher2 min readPublished
Suspected ransomware takes down about 500 servers at Osaka Metropolitan University
Osaka Metropolitan University cancelled classes after a suspected ransomware attack stopped about 500 servers, Japanese media reported. Records on at least 130,000 current and former students, faculty and others may be exposed, though the university has not confirmed any theft.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Systems for academic administration, educational support, financial accounting, payroll, human resources and library services went down, along with the websites and internal network.
- OMU says it believes ransomware caused the outage and is investigating the attack with outside cybersecurity specialists.
- The university has reported the incident to Japan's data protection authority and other government agencies.
- Classes are cancelled through at least Thursday, with in-person teaching due to resume Friday and online classes restarting as system recovery allows.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure The possible exposure goes beyond OMU's own rolls to data tied to Osaka Prefecture University and Osaka City University, so people whose records date from before the 2022 merger may be in the affected set.
- capability If the data was taken, names, addresses and email addresses give an attacker enough to send phishing addressed to each person by name.
- constraint With no attacker named and no ransom demand disclosed, other Japanese institutions have no group or indicators from this incident to check against their own networks.
OMU is one of Japan's largest universities [18], and some of its services kept running. Entrance exam applications and enrollment procedures stayed available because they are hosted on external servers, according to the university [13]. The electronic medical record system at the university hospital was not affected, and the hospital kept providing medical services [14]. The veterinary clinical center also stayed open [14].
Both figures that size the attack are second-hand. Japanese media reported the 500 stopped servers and the 130,000 possibly exposed people, citing university officials at a press conference on Monday [8][1]. In its own statement on Tuesday, OMU said its internal network and email were down [6]. It also said it was still investigating whether any information had leaked [4].
The outage began late last week, according to The Record [5]. The report does not describe how the attackers got in.
On the published record, this is a single incident. It comes as several other Japanese organisations have disclosed breaches, and The Record reports no evidence that they are connected [15]. Over the weekend Nikkei disclosed that a compromised employee account had sent about 9,000 malicious emails to contacts inside and outside the company, some of whom were sources for its journalism [16]. Brokerage Daiwa Securities, the delivery companies Yamato Transport and Sagawa Express, insurer Dai-ichi Life and broadcast equipment maker Ikegami Tsushinki have also disclosed incidents recently [17].
What to watch
- A ransomware group claiming OMU or posting its data, which would confirm theft and give defenders a named actor to track.
- The outside investigators' finding on whether personal data left the network, and any notice sent to the people affected.
- Whether online classes and the payroll, HR and accounting systems are back when in-person teaching resumes on Friday.