Osaka Metropolitan University, one of Japan's prominent educational institutions, faced a significant disruption due to a suspected ransomware attack that started late last week. This incident compelled the university to shut down a major portion of its IT infrastructure, leading to the cancellation of classes and rendering its internal network, email, and various academic systems inaccessible. The university, collaborating with external cybersecurity experts, is actively investigating the breach, although the attackers remain unidentified and it is unclear if a ransom demand has been made. The attack has impacted critical systems for academic administration, financial accounting, and more, affecting approximately 500 servers. Reports suggest that personal information of about 130,000 individuals linked to the university may have been compromised. However, the university has yet to confirm any data theft. In response, Osaka Metropolitan University has informed Japan's data protection authority and other relevant agencies. While classes are expected to resume soon, online classes will depend on the restoration of systems. Fortunately, systems related to entrance exams, enrollment, and medical records at the university hospital were not affected, as they are hosted externally. This incident arises amidst a series of recent cyberattacks in Japan, affecting various sectors but showing no direct connection to each other.
Ransomware Attack Disrupts Operations at Osaka Metropolitan University
Osaka Metropolitan University cancels classes after a ransomware outage affecting internal network, email and academic systems.
Executive Summary
Osaka Metropolitan University suffered a suspected ransomware attack, disrupting its IT systems and forcing class cancellations. The attack potentially compromised data of 130,000 individuals, and the university is investigating with cybersecurity experts.
Actionable Insights
- Conduct a thorough security audit of all IT systems to identify vulnerabilities.
- Enhance data encryption protocols to protect sensitive information.
- Implement regular cybersecurity training for staff and students to recognize phishing attempts.
Original source
therecord.media

