Security Guides
Osaka Metropolitan University ransomware attack (data on about 130,000 people at risk, per reports): what students, alumni and staff should do
A ransomware attack took down Osaka Metropolitan University's core IT systems and cancelled classes through October 8. Based on the university's official notices and major news reports: how students, alumni and staff can avoid fake messages, and the backup lessons for other organizations.
For: current students, alumni and staff of Osaka Metropolitan University, people considering applying there, and IT staff at universities, companies and local governments that run many servers on a virtualization platform. This article is based on the official notices from Osaka Metropolitan University and major news reports, and does not cover attack techniques.
What students, alumni and staff should do now
Check notices from the OMU Entrance page
The main website (www.omu.ac.jp) is down. The university says it posts the latest information on classes and admissions on the OMU Entrance page (https://e.omu.ac.jp/). On October 3 it also opened a temporary notice site (https://www.omu.moe/) to use until the official website is restored, and this address appears in the press conference handout.
Because the temporary site uses an unfamiliar domain, it is harder to tell apart from look-alike fake sites. Open it by following the link on the Entrance page you bookmarked, not from links in emails or texts.
Do not follow links or instructions in emails, texts or calls claiming to be from the university
News reports say the systems held names, home addresses, email addresses, student ID photos and more. A message with your correct name and student details is not proof that it is genuine.
Do not respond to messages that ask you to enter your ID, password or card number on a linked page, whether they mention "apologies for the outage", "account reset", "student ID reissue" or "tuition or scholarship procedures". Ask about anything suspicious through a contact point you found on the Entrance page (how to spot fakes: What is phishing).
Change passwords only after the university says so, and only on its genuine screen
As of October 6, the university's public notices contain no instruction to change passwords. If it issues one, check that the same instruction also appears on the Entrance page, then change your password on the university's genuine login screen.
If you use the same password as your university account on other services, change those to different passwords now (how to check: How to check if your password has leaked; a tool for keeping them separate: Choosing a password manager).
Do not reply to anyone who says they have your data
If you receive a message from someone claiming to hold your information and asking for payment or a reply, do not reply, pay, or enter anything on a linked page. Keep the message, and report it to the university and, in Japan, to the police consultation line #9110.
The recipient has no way to check whether the sender really has the data. Responding can mark your address as active and lead to more messages.
Alumni: compare any message with the university's own announcements
Unlike current students, alumni do not check university notices every day, so fake messages are harder to notice. If you get a message about "confirming the alumni list", "alumni association fees" or "issuing certificates", check whether the same information appears on the Entrance page or the temporary notice site.
As of October 6, the university's official notices do not say which alumni are covered (how many years back, or whether graduates of its predecessors, Osaka City University and Osaka Prefecture University, are included).
What happened (from Osaka Metropolitan University's notices)
The university issued its first and second notices on October 2, held a press conference on October 5, and posted a summary of the conference and the handout on its temporary notice site on October 6. Unless stated otherwise, the following is based on the university's notices and handout.
October 2, 2026, around 0:20 a.m.
The contractor responsible for maintenance noticed the servers of the information infrastructure system shutting down one after another and began investigating.October 2, around 1:40–4:00 a.m.
The contractor notified the university's IT department. Staff went on site, and the investigation found that a group of virtual servers had stopped and that some data showed signs of tampering.October 2, morning
Around 7 a.m., class cancellations were announced on the Entrance page. Around 8 a.m. the university reported to Osaka Prefecture and Osaka City, and at 8:15 it set up a crisis response headquarters headed by the president. Around 11 a.m. it reported to the Ministry of Education, information security organizations and the police.October 2, afternoon
First notice (cause under investigation) and second notice issued. Classes were cancelled through October 8, with in-person classes planned to resume from October 9.October 3, around 7:30 a.m.
A temporary website for announcements was opened.October 5
Around 10 a.m. the university contacted the Personal Information Protection Commission. At a press conference from 4 p.m., it said it had concluded the cause was a ransomware attack.
- What happened
- From the early hours of October 2, a large-scale failure hit the university's virtualization platform. A group of virtual servers stopped, and some data showed signs of tampering
- Cause
- Concluded to be a cyberattack, namely a ransomware attack. The cause and the damage are being investigated with help from outside specialist firms
- Main systems affected
- Campus network, OMU Mail, the corporation's websites, the staff portal, office PCs (staff cannot log in), finance and accounting, HR and payroll, academic affairs, learning support systems, the admissions database, the library system (the handout describes this as a partial list)
- Reported as unaffected
- The first notice said the systems of the university hospital and the veterinary medical center were unaffected. The online application and enrollment sites run on external servers and can be used
- Personal data
- Whether it was leaked is under investigation. The university reported to the Personal Information Protection Commission and will confirm the facts based on the specialists' findings
- Reported to
- Osaka Prefecture and Osaka City, the Ministry of Education, the police, information security organizations including JPCERT (Japan's computer security incident coordination center), and the Personal Information Protection Commission
- Contact
- Applications and enrollment: Admissions Office, 072-254-9117. A list of contact points is in the "お問い合わせ先について" (contact points) notice on the temporary notice site
What news reports say
The October 5 press conference was covered by Kyodo News, Nikkei, the Sankei Shimbun, the Asahi Shimbun, Kansai TV, Yomiuri TV and others. Figures that do not appear in the university's official notices are treated as news reports, as follows.
What several major outlets agree on
- About 500 servers stopped
- Much of the backup data was also encrypted (Kansai TV, Yomiuri TV)
- Personal data on at least about 130,000 people, including current students and alumni, may have been leaked
- The stored data includes names, home addresses, email addresses and student ID photos
Not confirmed, or differs between reports
- Whether personal data was actually leaked (the university is investigating)
- Other items such as phone numbers (reports differ)
- How far staff and graduates of the predecessor universities are included
- Whether a ransom was demanded (the university declined to comment, citing the investigation)
How to read it: 130,000 is not a confirmed number of people whose data leaked
The Asahi Shimbun and others describe about 130,000 people as the amount of personal data stored in the affected systems. The university itself says whether data was leaked is under investigation.
Fake messages can arrive while everyone waits for confirmation. Even before you know whether you are affected, the steps above are worth starting today.
What is particular to this incident: when a virtualization platform stops, hundreds of servers stop at once
A virtualization platform runs many servers (virtual servers) together on a set of physical servers. It reduces hardware and simplifies management, but when that base stops, every server running on it stops too.
According to the university, the failure of its virtualization platform stopped a group of virtual servers, and very different systems, from the network and email to academic affairs and payroll, became unusable at the same time. News reports say much of the backup data that would be used for recovery was also encrypted. The university has not disclosed how the attackers got in or how far the encryption spread, so what follows is about this kind of setup in general.
Same management domain
Virtualization platform admin account
↓ controls both
Hundreds of virtual servers
Backups
→ production and backups become unusable together
Separate management domains
Virtualization admin
Backup-only admin (with MFA)
↓ separate permissions
Hundreds of virtual servers
Copy that cannot be deleted for a set period, or kept offline
→ even if production stops, there is something to restore from
Having backups is not enough if they sit where the same production permissions can reach them; in an incident they can become unusable too. In the 2021 Handa Hospital (Tsurugi Town) incident, the investigation report also recorded that the backup server was among the encrypted servers. What this incident adds is scale. To restore hundreds of servers, you need not only a surviving copy but also a decided order and a known number of hours to bring them back.
For organizations running many servers on a virtualization platform
The points below do not claim that Osaka Metropolitan University's response was inadequate. They are precautions drawn from the facts in the notices and reports. The basics of the 3-2-1 rule and restore testing are in Backup basics (the 3-2-1 rule). Here we add what is specific to virtualization platforms.
Keep one backup that the virtualization admins cannot delete
First, list which people and which accounts can delete or overwrite backups. If the virtualization platform's admin account, or the admin of the directory that manages everyday user accounts, can delete them, the backups are in the same management domain as production.
As a first step, create a separate admin account just for backups, protect it with multi-factor authentication, and keep at least one copy either in a setting where it cannot be deleted or overwritten for a set period (immutable storage) or in storage that is normally disconnected from the network. Many backup products and cloud storage services offer a feature that blocks deletion during the retention period.
Measure restore drills in servers and hours
Measure not only "can we restore?" but "how many hours does it take to restore the systems we need to resume teaching or business?" For a university, decide the order needed to resume in advance, for example authentication, email, the learning management system, academic affairs, then the network.
Once a year, restore the top 10 servers from the disconnected copy into a separate environment, and record how long it takes. Multiply that by the number of servers to estimate how long a full restore would take. If the estimate is too long, that is a sign to rethink how backups are taken or how priorities are set.
Prepare and publicize a channel that still works when the platform is down
The university's notices show that its online application site, run on external servers, kept working, that it could announce class cancellations on the Entrance page on the morning of the outage, and that it opened a temporary notice site the next morning. When email and the official website go down together, the means of reaching users disappears.
Prepare an outage notice page in normal times that runs with a different provider and different admin accounts from production. If you tell students and partners its address in advance, they will not have to guess whether an unfamiliar domain is fake during an outage.
How ransomware works and how organizations can prepare is covered in What is ransomware, and cases where hospital systems stopped are in Hospitals whose care was disrupted by cyberattacks in 2026.
Sources (public record)
The facts in this article are based on the public information below. We do not speculate on attack methods or causes the university has not disclosed. Figures that come only from news reports are identified as such in the text.
- Osaka Metropolitan University, "本学情報基盤システムにおける障害の発生について【第1報】" (first notice on the failure of the information infrastructure system, October 2, 2026) — temporary notice site
- Osaka Metropolitan University, "本学情報基盤システムにおける障害の発生について【第2報】" (second notice, October 2, 2026) — temporary notice site
- Osaka Metropolitan University, "情報基盤システムにおける障害に関する記者会見を実施" (press conference held, October 6, 2026) and the press conference handout (October 5) — temporary notice site / handout (PDF)
- Osaka Metropolitan University, OMU Entrance page (outage information and class cancellation notices) — e.omu.ac.jp
- NHK News (report on the university's press conference, October 5, 2026) — news.web.nhk
- Kyodo News, "大阪公立大にランサム攻撃 個人情報、13万人流出恐れ" (October 5, 2026, via Kahoku Shimpo Online) — kahoku.news
- Nikkei, "大阪公立大学にランサム攻撃 個人情報、13万人流出恐れ" (October 5, 2026) — nikkei.com
- The Sankei Shimbun, "大阪公立大の大規模システム障害、サイバー攻撃が原因か 13万人超の個人情報流出恐れ" (October 5, 2026, via Yahoo! News Japan) — news.yahoo.co.jp
- The Asahi Shimbun, "大阪公立大のシステム障害「ランサムウェアによる攻撃」大学が発表" (October 5, 2026, via Yahoo! News Japan) — news.yahoo.co.jp
- Kansai TV, "大阪公立大 大規模システム障害の原因は「ランサムウェアによるサイバー攻撃」か" (October 5, 2026) — ktv.jp
- Yomiuri TV, "大阪公立大学にサイバー攻撃か サーバー500台停止し全学部休講" (October 5, 2026, via Infoseek News) — news.infoseek.co.jp
- Government of Japan public relations, "警察に対する相談は警察相談専用電話「#9110」番へ" (police consultation line #9110) — gov-online.go.jp
Update history
2026-10-06: First version, based on Osaka Metropolitan University's first and second notices of October 2, the October 5 press conference and its handout, and major news reports. The university says whether personal data was leaked is under investigation; we will update this article when new facts are published.
Read next
- Protecting yourself from fake messages: What is phishing / Choosing a password manager
- Ransomware and backups: What is ransomware / Backup basics (the 3-2-1 rule) / The Handa Hospital incident
- Similar incidents in Japan: Medica Shuppan ransomware attack / Hospitals disrupted by cyberattacks
- Other 2026 incidents: Data breaches and cyberattacks in 2026 (Japan and worldwide)
FAQ
QWhat happened at Osaka Metropolitan University?
According to the university, a large-scale failure began in its virtualization platform in the early hours of October 2, 2026, and many systems stopped, including the campus network, OMU Mail, the corporation's and university's websites, the learning support system, the academic affairs system, finance and accounting, HR and payroll, and the library system. At a press conference on October 5, the university said it had concluded that the cause was a cyberattack, namely a ransomware attack.
QWas personal data leaked?
The university says whether personal data was leaked is still under investigation. News reports say the affected systems held personal data on at least about 130,000 people, including current students and alumni, and that this data may have been leaked. The figure of about 130,000 is reported as the amount of data stored in the affected systems, not as a confirmed number of people whose data was leaked.
QWhat kinds of information could be involved?
The university's official notices do not list the types of information. The items that several major news outlets agree on are names, home addresses, email addresses and student ID photos (face photos). Other items, such as phone numbers, differ between reports. Check the scope and the items in the university's official announcements.
QWhen will classes resume?
According to the university's second notice, all classes through Thursday, October 8 are cancelled, and in-person classes are planned to resume from Friday, October 9. The timing of online classes will depend on how recovery progresses. Extensions of assignment and application deadlines are announced on the OMU Entrance page and the temporary notice site.
QShould I change my university password?
As of October 6, 2026, the university's public notices contain no instruction to change passwords. If the university issues one, confirm it on the OMU Entrance page first, then change the password on the university's genuine screen. Do not change it through links in emails or texts. If you use the same password as your university account on other services, change those to different passwords now.
QWhat should I do if someone contacts me saying they have my data?
Do not reply, pay, or enter any details, and keep the message rather than deleting it. Report it to the university (using a contact point you found on the OMU Entrance page) and, in Japan, to the police consultation line #9110. According to news reports, the university said it could not comment on whether a ransom was demanded because the matter is under investigation.