Key takeaways

  • Osaka Metropolitan University (大阪公立大学), run by Osaka Prefecture and Osaka City, was hit by what it believes was a ransomware attack early on October 2, 2026.
  • Attackers got into the university's virtualization platform, and about 500 servers stopped. Most backups were encrypted too. Email, the student portal and academic systems are down, and there is no recovery date.
  • Data on at least 130,000 people, including students and graduates going back to 1995, was stored on the affected systems. Whether it was taken is under investigation.
  • All classes are cancelled until October 8. The university hospital and veterinary center are unaffected.

What happened#

Date (2026) Event
Oct 2, early morning Large-scale failure of the university's information systems across all campuses. The university learns of it from its IT vendor
Oct 2, 14:00 First report: cause unknown, no recovery date. Classes cancelled for the day
Oct 2, 18:00 Second report: classes cancelled until Oct 8. In-person classes to resume from Oct 9
Oct 5 Press conference: the university says the cause is likely a ransomware attack

According to reports of the press conference, the attackers got into the virtualization platform that runs many of the university's systems, and about 500 servers stopped. Most of the backups were also encrypted and cannot be used. The university has no date for recovery.

President Hiroyuki Sakuragi apologized. The university has reported the attack to the Osaka Prefectural Police, the Ministry of Education and the Personal Information Protection Commission, according to Nikkei. It has not said whether a ransom has been demanded or who is behind the attack.

What is down#

  • Campus network, email, the student portal and academic systems, on all campuses
  • The main website, www.omu.ac.jp. The university is posting updates on its entrance page and a temporary notice site

Not affected:

  • The university hospital and the veterinary clinical center, which are operating normally
  • Online application and enrollment sites for prospective students, which run on external servers. The application deadline has been extended to October 22

What may have been exposed#

The university says personal data on at least 130,000 people was stored on the affected systems. According to the press reports, it includes:

Data Source of report
Names, addresses, email addresses Nikkei, Jiji
Mobile phone numbers MBS
Student ID photos Nikkei

The people covered include current students, graduates, and faculty and staff. The data goes back to students of Osaka City University from 1995 and Osaka Prefecture University from 2005, the two universities that merged to form Osaka Metropolitan University in 2022. With an undergraduate intake of about 2,850, the merged university was the third-largest national or public university in Japan, after Osaka University and the University of Tokyo, when it opened, according to Nikkei.

Whether any of it was taken is still under investigation.

What we don't know yet#

The university has not said:

  • How the attackers got in, and when
  • Whether data was stolen as well as encrypted, and whether a ransom has been demanded
  • Which ransomware group is responsible. As of the morning of October 6, we found no listing on ransomware leak site trackers
  • When systems will be restored, and when online classes can resume
  • Whether it will notify each of the 130,000 people individually

The university's written notices still describe the cause as "under investigation". The details above come from reports of the October 5 press conference.

Our analysis#

One platform, 500 servers, and the backups#

The most important detail is where the attackers landed: the virtualization platform. When many systems run as virtual machines on shared infrastructure, control of that layer is control of all of them, and of any backups stored or managed within reach. That is how one intrusion becomes 500 stopped servers and backups that cannot be used.

This is a common pattern in ransomware attacks: many major ransomware groups have encryptors built specifically for hypervisors, so that a single foothold in the virtualization layer can stop hundreds of servers at once.

It is the pattern the police figures keep showing. In the NPA's ransomware statistics, most victims had backups, but most of those who tried could not restore from them, usually because the attackers had encrypted or deleted the backups too. Backups only help if the attacker cannot reach them: offline, immutable, or managed with separate credentials. The university has not said how its backups were set up.

Thirty years of data#

Data on students going back to 1995 was on the affected systems. That is not unusual for a university: alumni records, certificates and contact lists build up over decades. But it means the people at risk include graduates who left the university, or its predecessors, long ago and may not expect to be affected.

We have seen the same issue in other breaches this month: Dai-ichi Life held records on former office staff going back to 1967, and Times Car held data on former members and on people who never completed sign-up. Data that is no longer needed day to day still has to be protected, or deleted.

Found by the vendor#

According to the first report, the university learned of the failure through contact from its IT vendor, and the investigation is being carried out with the outsourced operator of its systems. Many Japanese organizations, universities included, rely on outside companies to run their infrastructure. That means that how quickly an attack is spotted, and how the systems were configured, may depend as much on the operator as on the university.

Keeping students informed#

With its main website down, the university has kept communicating through a separate entrance page and a temporary notice site, both apparently hosted outside the affected systems. That is the right approach. One caution: the temporary site uses a domain outside omu.ac.jp. Students and others should reach it through the university's entrance page, e.omu.ac.jp, rather than through links in emails or messages, since scammers often imitate emergency notices.

What this means for readers#

  • If you studied or worked at Osaka Metropolitan University, Osaka City University (since 1995) or Osaka Prefecture University (since 2005), your name, address, email, phone number and possibly your student ID photo may have been on the affected systems.
  • Be suspicious of messages about the incident, especially ones asking you to log in, pay, or "check" whether you are affected. Get updates from e.omu.ac.jp.
  • For organizations running virtualized infrastructure, treat the virtualization management layer as one of your most critical systems, and keep at least one copy of backups that it cannot reach.

Japanese terms at a glance#

Japanese Reading Meaning
大阪公立大学 Ōsaka Kōritsu Daigaku Osaka Metropolitan University
情報基盤システム jōhō kiban shisutemu Information infrastructure systems
仮想化基盤 kasōka kiban Virtualization platform
休講 kyūkō Class cancellation
運用委託事業者 un'yō itaku jigyōsha Outsourced IT operator
臨時お知らせサイト rinji oshirase saito Temporary notice site

We will update this article when the university publishes the results of its investigation or a recovery date.