Skip to content
Security & Trust

A suspected ransomware attack halted classes at a Japanese university

About 500 servers stopped at Osaka Metropolitan University, while externally hosted and hospital systems kept running

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
A suspected ransomware attack halted classes at a Japanese university
In brief
  • Osaka Metropolitan University says suspected ransomware knocked out its internal network and email, and it cancelled classes through at least Thursday.
  • The outage is consistent with many functions relying on shared infrastructure, though the university has not said how its systems were connected or how the intrusion began.
  • Leaders should map which critical services share one network, which run elsewhere, and whether staff could work for days without email.

An outage can hint at a map. The systems that fail together, and those that do not, suggest which parts of an organisation depend on each other. When Osaka Metropolitan University (OMU) lost its systems, it offered a partial glimpse of that map.

What happened

The Record reported on October 6 that OMU, one of Japan's largest universities, cancelled classes after a suspected ransomware attack. The attack began late last week. The internal network, email and many other systems went down.

Classes are off through at least Thursday. In-person teaching is due to restart on Friday. Online classes will restart as recovery allows.

OMU is working with outside security experts. It has not named the attackers. It has not said whether it received a ransom demand.

About 500
Servers that stopped operating
Source: Japanese media reports citing OMU officials at a Monday press conference, as relayed by The Record (October 6, 2026)

What went down, and what did not

The outage hit payroll, accounting, human resources, the library and student support. It also hit academic administration and the university's websites.

Some services stayed up. Entrance exam applications and enrolment run on outside servers, so they kept working. The hospital's electronic medical records were not affected, and care went on. The veterinary clinical centre also kept running.

The Record does not say why the hospital system was spared. Nobody should assume a particular design explains it.

How ransomware can stop hundreds of servers at once

This section is general background. It is not a finding about OMU. The university has not said how the attackers got in or how its systems were linked.

Ransomware is software that locks files. The attackers then demand payment to unlock them.

Attackers rarely start at the most valuable server. They often start with one stolen password or one infected laptop.

From there, they look for a way to spread. On a flat network, most machines can reach most others. Attackers use that to hop from one machine to the next.

Many organisations also keep every account in one central directory. If attackers seize a powerful account there, it works like a master key. They can then run the locking software on many servers at once.

That is one way hundreds of servers can stop together. Payroll, email and the library have different owners. If they share a network and the same accounts, they share the same fate.

Two design choices help. The first is segmentation. It splits a network into zones, with strict rules on which zones may talk to each other. An attacker who enters one zone meets walls.

The second is hosting a service outside the main network, with its own logins. That keeps it out of reach of the spread. Neither choice is a full defence. Both limit how far one break-in can go.

What the outage suggests

OMU's outage is consistent with many functions relying on shared infrastructure. The university has not said how its systems were connected. The exam and enrolment systems stayed online because they sit on external servers. That fits the pattern above. It does not prove it.

The lesson here is a way of seeing risk. Resilience depends on how many services share one foundation. The strength of each single service matters less. Students could not attend class. Staff rely on payroll and HR systems that were among those hit.

What is still unknown

Japanese media reports say 130,000 or more people may be affected. They include current and former students and staff, and others linked to the university.

The data at risk could include names, addresses and email addresses. The reports also mention data tied to the two older institutions that combined in 2022 to create OMU: Osaka Prefecture University and Osaka City University.

At least 130,000
People whose data may have been exposed
Source: Japanese media reports relayed by The Record (October 6, 2026)

OMU has not confirmed that any personal data was stolen. It is still checking. It has told Japan's data protection authority and other government bodies.

The Record notes other recent cyber incidents at Japanese companies, including Nikkei and Daiwa Securities. It says there is no evidence they are linked to the OMU attack.

Questions for your next leadership meeting

First, list the services your organisation cannot run without. Ask which of them share one network and one set of logins. Then ask what stops an intruder moving from one to the next.

Second, ask which critical services are hosted elsewhere. Has anyone tested running them while the main network is down?

Third, ask how staff would communicate if email were gone for days. OMU's email was among the systems lost.

Fourth, confirm who you would notify, and how fast. OMU reported to its data protection authority while its investigation was still open.

A shared network is a shared fate. Know how many of your services ride on one.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: The Record.

Share this insight